Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-6837-qgrc-x5p6 | Jenkins has a CSRF vulnerability on the login form |
Wed, 17 Dec 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:* cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:* |
Thu, 11 Dec 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | org.jenkins-ci.main/jenkins-core: Jenkins cross-site request forgery | |
| Weaknesses | CWE-613 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 10 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins
Jenkins jenkins |
|
| Vendors & Products |
Jenkins
Jenkins jenkins |
Wed, 10 Dec 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-352 | |
| Metrics |
cvssV3_1
|
Wed, 10 Dec 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A cross-site request forgery (CSRF) vulnerability in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier allows attackers to trick users into logging in to the attacker's account. | |
| References |
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-12-10T17:27:25.419Z
Reserved: 2025-12-09T17:33:01.215Z
Link: CVE-2025-67639
Updated: 2025-12-10T17:27:19.424Z
Status : Analyzed
Published: 2025-12-10T17:15:56.400
Modified: 2025-12-17T20:23:49.317
Link: CVE-2025-67639
OpenCVE Enrichment
Updated: 2025-12-10T21:33:14Z
Github GHSA