CNNVD-202510-4012 Information

CNNVD ID

CNNVD-202510-4012

CVE-2025-64136

  • CNNVD Published: 2025-10-29

Description (Chinese)

Jenkins和Jenkins plugin都是Jenkins开源的产品。Jenkins是一个应用软件。一个开源自动化服务器Jenkins提供了数百个插件来支持构建,部署和自动化任何项目。Jenkins plugin是一个应用软件插件。 Jenkins plugin Themis 1.4.1及之前版本存在安全漏洞,该漏洞源于容易受到跨站请求伪造攻击。

Description (English)

Jenkins and Jenkins plugin are all Jenkins open-source products. Jenkins is an application. Jenkins, an open-source automated server, provided hundreds of plugins to support construction, deployment and automation of any project. Jenkins plugin is an application plugin. There is a security gap in Jenkins plugin Themis 1.4.1 and earlier versions, which stems from the vulnerability to cross-site requests for false attacks.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

Jenkins

Published

2025-10-29

Last Modified

2026-02-24

References

https://www.jenkins.io/security/advisory/2025-10-29/#SECURITY-3517 https://access.redhat.com/security/cve/cve-2025-64136

Patch

https://www.jenkins.io/security/advisory/2025-10-29/#SECURITY-3517

Share on: