Record summary

CVE-2025-59474 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check in the sidepanel of a page intentionally accessible to users lacking Overall/Read permission, allowing attackers without Overall/Read permission to list agent names through its sidepanel executors widget.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Oct 17, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 25, 2025 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Default status: affected

CVE ListBefore 2.387unaffected
2.516.3 to < 2.516.*unaffected
2.528 to < *unaffected

org.jenkins-ci.main:jenkins-core

Browse Maven / org.jenkins-ci.main:jenkins-core
GitHub AdvisoryBefore 2.516.3 · Fixed in 2.516.3affected
2.517 to < 2.528 · Fixed in 2.528affected

Nuclei templates

1
ProjectDiscoveryMEDIUMJenkins Sidepanel - Unauthorized Agent/Queue Exposure

Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check in the sidepanel of a page intentionally accessible to users lacking Overall/Read permission, allowing attackers without Overall/Read permission to list agent names through its sidepanel executors widget.

Impact

Attackers can list agent names without required permissions, potentially exposing sensitive infrastructure details.

Remediation

Update to a version later than 2.527 or LTS later than 2.516.2.

Authorsivaldivieso
Template tagscvecve2025jenkinssidepanelunauthvkevvuln
Shodan: product:"jenkins"

Source: ProjectDiscovery

References

3