1
Multiple vulnerabilities were identified in Jenkins. A remote attacker could exploit some of these vulnerabilities to trigger spoofing, denial of service condition and sensitive information disclosure on the targeted system.
Impact
- Information Disclosure
- Spoofing
- Denial of Service
System / Technologies affected
- Jenkins weekly 2.540 and earlier versions
- Jenkins LTS 2.528.2 and earlier versions
Solutions
Before installation of the software, please visit the vendor web-site for more details.
Apply fixes issued by the vendor:
- https://www.jenkins.io/security/advisory/2025-12-10/