CVE-2025-67636 Overview
CVE-2025-67636 is a missing authorization vulnerability in Jenkins, the widely deployed open-source automation server. The flaw affects Jenkins 2.540 and earlier, and LTS 2.528.2 and earlier. It allows authenticated attackers holding only View/Read permission to view encrypted password values stored in views. The issue is tracked under the Jenkins security advisory SECURITY-1809 and mapped to CWE-862: Missing Authorization.
Critical Impact
Attackers with low-privileged View/Read access can retrieve encrypted password values from Jenkins views, exposing sensitive credential material for offline analysis or lateral movement.
Affected Products
- Jenkins weekly releases 2.540 and earlier
- Jenkins LTS 2.528.2 and earlier
- Jenkins instances exposing views containing password-type parameters
Discovery Timeline
- 2025-12-10 - Jenkins publishes security advisory SECURITY-1809
- 2025-12-10 - CVE-2025-67636 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-67636
Vulnerability Analysis
The vulnerability stems from an absent permission check in the code path that renders view configuration data. Jenkins views can contain configuration fields backed by encrypted password values. When a user requests view details, Jenkins fails to verify that the caller holds Configure or equivalent privileges before returning the encrypted values. Any user with View/Read permission receives the encrypted secrets in the response.
While the values are returned in encrypted form, exposure of the ciphertext undermines the defense-in-depth model Jenkins enforces around secrets. Attackers with sufficient context or additional Jenkins access can attempt to decrypt these values or use them in credential-stuffing scenarios against other systems.
Root Cause
The root cause is a missing authorization check [CWE-862] on the view-rendering endpoint. Jenkins treats View/Read as adequate to view a view, but does not further constrain access to secret-bearing fields within that view. Sensitive fields inherit the same access scope as non-sensitive metadata.
Attack Vector
Exploitation requires network access to the Jenkins controller and a valid account holding View/Read on a target view. The attacker requests view details through the Jenkins web interface or API and parses encrypted password values from the returned content. No user interaction is required beyond the attacker's own authenticated session. Refer to the Jenkins Security Advisory SECURITY-1809 for the specific endpoints and view types affected.
Detection Methods for CVE-2025-67636
Indicators of Compromise
- Unexpected View/Read API calls from accounts that do not normally interact with the affected views.
- Access log entries showing repeated retrieval of view configuration endpoints by low-privileged users.
- Correlated authentication events where the same account queries multiple views in short succession.
Detection Strategies
- Review Jenkins access logs for GET requests against view endpoints originating from accounts limited to View/Read.
- Baseline normal view-access patterns per user and alert on deviations, especially bulk enumeration.
- Correlate Jenkins audit events with downstream authentication failures on systems whose credentials are stored as Jenkins secrets.
Monitoring Recommendations
- Forward Jenkins access and audit logs to a centralized log platform for retention and query.
- Monitor for anomalous read activity against views containing password parameters.
- Track privilege assignments over time and alert when View/Read is granted broadly across an organization.
How to Mitigate CVE-2025-67636
Immediate Actions Required
- Upgrade Jenkins weekly to release 2.541 or later, and Jenkins LTS to 2.528.3 or later, per the Jenkins Security Advisory SECURITY-1809.
- Audit view configurations and remove password-type parameters that are not required.
- Review users and groups granted View/Read and remove access that is not operationally justified.
Patch Information
Jenkins addressed CVE-2025-67636 in the December 10, 2025 security release. Administrators should upgrade to Jenkins weekly 2.541 or newer, or Jenkins LTS 2.528.3 or newer, as documented in the vendor advisory. The patch adds the missing permission check on the view-rendering path so encrypted password values are only returned to users with adequate configuration privileges.
Workarounds
- Restrict Jenkins network exposure to trusted administrative networks pending patch deployment.
- Reduce View/Read grants to the minimum required user set until the upgrade completes.
- Rotate any credentials suspected to have been exposed through view enumeration.
# Verify Jenkins version after patching
curl -s -u "$JENKINS_USER:$JENKINS_TOKEN" \
"$JENKINS_URL/api/json?tree=version" | jq .version
# Enumerate users holding View/Read to prune excess access
curl -s -u "$JENKINS_USER:$JENKINS_TOKEN" \
"$JENKINS_URL/asynchPeople/api/json?depth=1" | jq '.users[].user.fullName'
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
