CVE-2025-31720Missing Authorization in Jenkins

Severity
4.3MEDIUMNVD
EPSS
0.1%
top 70.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 2

Description

A missing permission check in Jenkins 2.503 and earlier, LTS 2.492.2 and earlier allows attackers with Computer/Create permission but without Computer/Extended Read permission to copy an agent, gaining access to its configuration.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages9 packages

🔴Vulnerability Details

2
OSV
Jenkins Missing Permission Check2025-04-02
GHSA
Jenkins Missing Permission Check2025-04-02

📋Vendor Advisories

2
Red Hat
jenkins: Missing permission check allows retrieving agent configurations2025-04-02
Jenkins
Jenkins Security Advisory 2025-04-022025-04-02
CVE-2025-31720 — Missing Authorization in Jenkins | cvebase