Vulnerability Bulletins

CVE-2025-64140

   
Affected software JENKINS
 
Jenkins Azure CLI Plugin 0.9 and earlier does not restrict which commands it executes on the Jenkins controller, allowing attackers with Item/Configure permission to execute arbitrary shell commands.

Link:

https://nvd.nist.gov/vuln/detail/CVE-2025-64140