CVE-2025-47886 Details
Description
A cross-site request forgery (CSRF) vulnerability in Jenkins Cadence vManager Plugin 4.0.1-286.v9e25a_740b_a_48 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified username and password.
A cross-site request forgery (CSRF) vulnerability exists in the Jenkins Cadence vManager Plugin versions 4.0.1-286.v9e25a_740b_a_48 and earlier. This vulnerability allows attackers to connect to a URL of their choice using a specified username and password. The plugin does not require POST requests for these connections, further facilitating the CSRF exploitation.
Users of the Cadence vManager Plugin should update to version 4.0.1-288.v8804b_ea_a_cb_7f, which addresses this vulnerability by requiring POST requests and Item/Configure permission for the affected form validation method.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 15, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.jenkins.io/security/advisory/2025-05-14/#SECURITY-3548 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-352 | Cross-Site Request Forgery (CSRF) | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| jenkins cadence vmanager | <= 4.0.1-286.v9e25a_740b_a_48 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 12, 2025 | Initial Analysis | [email protected] |
| May 15, 2025 | CVE Modified | CISA-ADP |
| May 14, 2025 | New CVE Received | [email protected] |