Vulnerability Details CVE-2025-24401
Jenkins Folder-based Authorization Strategy Plugin 217.vd5b_18537403e and earlier does not verify that permissions configured to be granted are enabled, potentially allowing users formerly granted (typically optional permissions, like Overall/Manage) to access functionality they're no longer entitled to.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 26.1%
CVSS Severity
CVSS v3 Score 6.8
Products affected by CVE-2025-24401
-
cpe:2.3:a:jenkins:folder-based_authorization_strategy:-
-
cpe:2.3:a:jenkins:folder-based_authorization_strategy:1.0
-
cpe:2.3:a:jenkins:folder-based_authorization_strategy:1.0.1
-
cpe:2.3:a:jenkins:folder-based_authorization_strategy:1.0.2
-
cpe:2.3:a:jenkins:folder-based_authorization_strategy:1.1
-
cpe:2.3:a:jenkins:folder-based_authorization_strategy:1.2
-
cpe:2.3:a:jenkins:folder-based_authorization_strategy:1.3
-
cpe:2.3:a:jenkins:folder-based_authorization_strategy:1.4
-
cpe:2.3:a:jenkins:folder-based_authorization_strategy:217.vd5b_18537403e