Description

Jenkins MCP Server Plugin 0.84.v50ca_24ef83f2 and earlier does not perform permission checks in multiple MCP tools, allowing attackers to trigger builds and obtain information about job and cloud configuration they should not be able to access.

INFO

Published Date :

2025-10-29T13:29:40.401Z

Last Modified :

2025-11-04T21:14:23.718Z

Source :

jenkins
AFFECTED PRODUCTS

The following products are affected by CVE-2025-64132 vulnerability.

Vendors Products
Jenkins
  • Jenkins
  • Mcp Server
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-64132.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact