
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67636 is a missing permission check vulnerability in Jenkins core (tracked as SECURITY-1809) that allows attackers with View/Read permission to view encrypted password values in views. It affects Jenkins weekly versions 2.540 and earlier, and LTS versions 2.528.2 and earlier. The vulnerability was disclosed on December 10, 2025, as part of the Jenkins Security Advisory 2025-12-10. It carries a CVSS v3.1 base score of 4.3 (Medium) (Jenkins Advisory, GitHub Advisory).
The root cause is a missing authorization check (CWE-862) in Jenkins core's handling of password fields in views. Jenkins does not perform a permission check to determine whether a password field should be redacted before rendering it in a view, allowing users with only View/Read permission to see encrypted password values that should require View/Configure permission to access. Exploitation requires a specific precondition: a plugin must implement a view page that displays a password field without performing a View/Configure permission check and without setting the readOnlyMode variable introduced by JEP-224. As of the advisory publication, the Jenkins security team was not aware of any exploitable plugin implementation meeting these conditions (Jenkins Advisory, GitHub Advisory).
Successful exploitation results in a limited confidentiality breach — specifically, an attacker with low-privilege View/Read access could read encrypted password values displayed in Jenkins views, potentially exposing sensitive credentials stored in the Jenkins configuration. There is no impact on integrity or availability. The practical risk is constrained by the requirement for a vulnerable plugin implementation, which the Jenkins security team had not identified at the time of disclosure (Jenkins Advisory).
Jenkins has released fixed versions that enforce View/Configure permission checks before displaying encrypted password values in views: Jenkins weekly 2.541 and Jenkins LTS 2.528.3. Administrators unable to upgrade immediately can disable the security fix as a temporary workaround by setting the system property hudson.Functions.nonRecursivePasswordMaskingPermissionCheck=true, though this is not recommended for production environments. Upgrading to the patched versions is the recommended remediation (Jenkins Advisory).
The vulnerability was reported by Daniel Beck of CloudBees, Inc. and was disclosed as part of a broader Jenkins security advisory covering multiple issues on December 10, 2025. Security scanning vendors including Tenable (Nessus plugin 278130) and Qualys have added detection for this CVE. No significant independent researcher commentary or notable media coverage specific to this vulnerability was identified beyond standard vulnerability database aggregation (Jenkins Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."