CVE-2025-59474 is a medium-severity vulnerability affecting Jenkins 2.527 and earlier, and LTS 2.516.2 and earlier. It allows unauthenticated attackers to list agent names via the sidepanel executors widget, even without Overall/Read permission, due to a missing permission check. The CVSS score is 5.3, indicating a network-based attack with low complexity and a low impact on confidentiality, but no impact on integrity or availability. While there is no evidence of active exploitation or Metasploit modules, a Nuclei template exists for detecting this vulnerability. Community discussion and media coverage are minimal, suggesting low public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.516.3CPE matchmatch criteria | cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:* | ||
< 2.528CPE matchmatch criteria | cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.