CVE-2025-31720 — Missing Authorization in Jenkins
Severity
4.3MEDIUMNVD
EPSS
0.1%
top 70.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 2
Description
A missing permission check in Jenkins 2.503 and earlier, LTS 2.492.2 and earlier allows attackers with Computer/Create permission but without Computer/Extended Read permission to copy an agent, gaining access to its configuration.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4