Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Jenkins Plugin Vulnerabilities: Info Leak, SMTP Injection, Privilege Escalation (CVE-2025-58458/7962/58459/58460)

Security Advisory SA-CORE-2025-003 Medium Jenkins
Affected:
  • Git client Plugin <= 6.3.2
  • Jakarta Mail API Plugin <= 2.1.3-2
  • global-build-stats Plugin <= 3.22.v22f4db_18e2dd
  • OpenTelemetry Plugin <= 3.1543.v8446b_92b_c6d6
Fixed in:
  • Git client Plugin: 6.3.3
  • global-build-stats Plugin: 3.47.v32a_eb_0493c4f
  • Jakarta Mail API Plugin: 2.1.3-3
  • OpenTelemetry Plugin: 3.1543.1545.vf5a_4ec123769
Referenced CVEs: CVE-2025-58459
文章内图片已隐藏以节省流量 · Upgrade to Pro to view images & offline archive

This content was auto-fetched from www.jenkins.io, cleaned by our LLM pipeline, and translated to English. View original.
Offline Archive

Offline screenshot & PDF are Pro-exclusive

Upgrade to Pro