CVE-2025-64132 Details
Description
Jenkins MCP Server Plugin 0.84.v50ca_24ef83f2 and earlier does not perform permission checks in multiple MCP tools, allowing attackers to trigger builds and obtain information about job and cloud configuration they should not be able to access.
A vulnerability exists in the Jenkins MCP Server Plugin in versions through 0.84.v50ca_24ef83f2, where permission checks are not properly enforced in several MCP tools. This oversight allows attackers to trigger builds and access job and cloud configuration information that should be restricted.
Users of the MCP Server Plugin should update to version 0.86.v7d3355e6a_a_18, which includes the necessary permission checks for the affected MCP tools.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 29, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2025/10/29/2 | CVE | Mailing ListThird Party Advisory |
| https://www.jenkins.io/security/advisory/2025-10-29/#SECURITY-3622 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| jenkins mcp server | < 0.86.v7d3355e6a_a_18 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 22, 2025 | Initial Analysis | [email protected] |
| Nov 4, 2025 | CVE Modified | CVE |
| Oct 29, 2025 | New CVE Received | [email protected] |
| Oct 29, 2025 | CVE Modified | CISA-ADP |