PT-2026-2493 · Jervis · Jervis

CVE-2025-68698

·

Publicado

2026-01-13

·

Atualizado

2026-01-13

CVSS v4.0

8.7

Alta

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Jervis versions prior to 2.2
Description Jervis, a library for Job DSL plugin scripts and shared Jenkins pipeline libraries, utilizes PKCS1Encoding, which is susceptible to Bleichenbacher padding oracle attacks. Modern systems should employ OAEP (Optimal Asymmetric Encryption Padding) for enhanced security. This issue has been addressed in version 2.2. A Bleichenbacher padding oracle attack exploits weaknesses in the PKCS#1 v1.5 padding scheme used in certain cryptographic algorithms.
Recommendations Update Jervis to version 2.2 or later.

Exploit

Correção

Use of a Broken Cryptographic Algorithm

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-68698
GHSA-MQW7-C5GG-XQ97

Produtos afetados

Jervis