CVE-2025-64132
published 2025-10-29CVE-2025-64132: Jenkins MCP Server Plugin 0.84.v50ca_24ef83f2 and earlier does not perform permission checks in multiple MCP tools, allowing attackers to trigger builds and…
PriorityP431medium5.4CVSS 3.1
AVNACLPRLUINSUCLILAN
EPSS
0.24%
14.8th percentile
Jenkins MCP Server Plugin 0.84.v50ca_24ef83f2 and earlier does not perform permission checks in multiple MCP tools, allowing attackers to trigger builds and obtain information about job and cloud configuration they should not be able to access.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | azure_cli_plugin | — | — |
| jenkins | byteguard_build_actions_plugin | — | — |
| jenkins | curseforge_publisher_plugin | — | — |
| jenkins | eggplant_runner_plugin | — | — |
| jenkins | extensible_choice_parameter_plugin | — | — |
| jenkins | jdepend_maven_plugin | — | — |
| jenkins | jdepend_plugin | — | — |
| jenkins | mcp_server | < 0.86.v7d3355e6a_a_18 | 0.86.v7d3355e6a_a_18 |
| jenkins | mcp_server_plugin | — | — |
| jenkins | nexus_task_runner_plugin | — | — |
| jenkins | openshift_pipeline_plugin | — | — |
| jenkins | publish_to_bitbucket_plugin | — | — |
| jenkins | saml_plugin | — | — |
| jenkins | start_windocks_containers_plugin | — | — |
| jenkins | themis_plugin | — | — |
| jenkins_project | jenkins_mcp_server_plugin | <= 0.84.v50ca_24ef83f2 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Jenkins MCP Server Plugin does not perform permission checks in multiple MCP tools
osv·2025-10-29
CVE-2025-64132 [MEDIUM] Jenkins MCP Server Plugin does not perform permission checks in multiple MCP tools
Jenkins MCP Server Plugin does not perform permission checks in multiple MCP tools
Jenkins MCP Server Plugin 0.84.v50ca_24ef83f2 and earlier does not perform permission checks in several MCP tools.
This allows to do the following:
- Attackers with Item/Read permission can obtain information about the configured SCM in a job despite lacking Item/Extended Read permission (`getJobScm`).
- Attackers with Item/Read permission can trigger new builds of a job despite lacking Item/Build permission (`triggerBuild`).
- Attackers without Overall/Read permission can retrieve the names of configured clouds (`getStatus`).
MCP Server Plugin 0.86.v7d3355e6a_a_18 performs permission checks for the affected MCP tools.
GHSA
Jenkins MCP Server Plugin does not perform permission checks in multiple MCP tools
ghsa·2025-10-29
CVE-2025-64132 [MEDIUM] CWE-862 Jenkins MCP Server Plugin does not perform permission checks in multiple MCP tools
Jenkins MCP Server Plugin does not perform permission checks in multiple MCP tools
Jenkins MCP Server Plugin 0.84.v50ca_24ef83f2 and earlier does not perform permission checks in several MCP tools.
This allows to do the following:
- Attackers with Item/Read permission can obtain information about the configured SCM in a job despite lacking Item/Extended Read permission (`getJobScm`).
- Attackers with Item/Read permission can trigger new builds of a job despite lacking Item/Build permission (`triggerBuild`).
- Attackers without Overall/Read permission can retrieve the names of configured clouds (`getStatus`).
MCP Server Plugin 0.86.v7d3355e6a_a_18 performs permission checks for the affected MCP tools.
Jenkins
Jenkins Security Advisory 2025-10-29
vendor_jenkins·2025-10-29·CVSS 7.5
CVE-2016-5597 [HIGH] Jenkins Security Advisory 2025-10-29
Title: Jenkins Security Advisory 2025-10-29
Jenkins Security Advisory 2025-10-29
Jenkins Security Home
For Administrators
Overview
Terminology
Vulnerabilities and Scoring
Security Advisories
Security Issues
Advisory Schedule
Vulnerabilities in Plugins
How We Fix Security Issues
For Reporters
Reporting Vulnerabilities
Jenkins CNA
For Maintainers
Overview
Vulnerabilities in Plugins
Jenkins Security Team
About
Contributions
This advisory announces vulnerabilities in the following Jenkins deliverables:
Azure CLI
Plugin
ByteGuard Build Actions
Plugin
Curseforge Publisher
Plugin
Eggplant Runner
Plugin
Extensible Choice Parameter
Plugin
JDepend
Plugin
MCP Server
Plugin
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-10-29
Published