PT-2026-2493 · Jervis · Jervis
CVE-2025-68698
·
Publicado
2026-01-13
·
Atualizado
2026-01-13
CVSS v4.0
8.7
Alta
| Vetor | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Jervis versions prior to 2.2
Description
Jervis, a library for Job DSL plugin scripts and shared Jenkins pipeline libraries, utilizes PKCS1Encoding, which is susceptible to Bleichenbacher padding oracle attacks. Modern systems should employ OAEP (Optimal Asymmetric Encryption Padding) for enhanced security. This issue has been addressed in version 2.2. A Bleichenbacher padding oracle attack exploits weaknesses in the PKCS#1 v1.5 padding scheme used in certain cryptographic algorithms.
Recommendations
Update Jervis to version 2.2 or later.
Exploit
Correção
Use of a Broken Cryptographic Algorithm
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Jervis