Samrocketman maintains a narrowly focused continuous-integration and deployment automation tool, Jervis, which sits in build pipelines and configuration management environments. The vendor's vulnerability profile concentrates on cryptographic and authentication deficiencies, including the use of broken or risky algorithms, predictable identifier generation, improper signature verification, and inadequate encryption strength—weaknesses that reflect the security-critical role of CI/CD tooling in controlling code deployment and secrets handling. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Samrocketman over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-68931HIGH Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, AES/CBC/PKCS5Padding lacks authentication, making it vulnerable to padding oracl | Jan 13, 2026 | 7.5 | 28 | NO | NO |
CVE-2025-68701HIGH Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses deterministic AES IV derivation from a passphrase. This vulnerabilit | Jan 13, 2026 | 7.5 | 28 | NO | NO |
CVE-2025-68698HIGH Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses PKCS1Encoding which is vulnerable to Bleichenbacher padding oracle a | Jan 13, 2026 | 7.5 | 28 | NO | NO |
CVE-2025-68704HIGH Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses java.util.Random() which is not cryptographically secure for timing | Jan 13, 2026 | 7.5 | 24 | NO | NO |
CVE-2025-68703HIGH Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, the salt is derived from sha256Sum(passphrase). Two encryption operations with t | Jan 13, 2026 | 7.5 | 24 | NO | NO |
CVE-2025-68702HIGH Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses padLeft(32, '0') when it should use padLeft(64, '0') because SHA-25 | Jan 13, 2026 | 7.5 | 22 | NO | NO |
CVE-2025-68925MEDIUM Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, the code doesn't validate that the JWT header specifies "alg":"RS256". This vuln | Jan 13, 2026 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Samrocketman.
Media articles that mention a CVE ID that affects a product developed by Samrocketman — matched by CVE ID, not by vendor name.