{"id":"GHSA-gm8g-fh49-qq6v","summary":"Jenkins global-build-stats Plugin missing permission check can result in graph IDs being enumerated","details":"Jenkins global-build-stats Plugin 322.v22f4db_18e2dd and earlier does not perform permission checks in its REST API endpoints, allowing attackers with Overall/Read permission to enumerate graph IDs. \n\nThis has been patched in version 347.v32a_eb_0493c4f.","aliases":["CVE-2025-58459"],"modified":"2025-11-05T20:51:58.480395Z","published":"2025-09-03T15:30:34Z","database_specific":{"cwe_ids":["CWE-284"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2025-09-03T22:22:41Z","nvd_published_at":"2025-09-03T15:15:39Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-58459"},{"type":"WEB","url":"https://github.com/jenkinsci/global-build-stats-plugin/commit/32aeb0493c4ff5423448576f477ac612f7a25138"},{"type":"PACKAGE","url":"https://github.com/jenkinsci/global-build-stats-plugin"},{"type":"WEB","url":"https://www.jenkins.io/security/advisory/2025-09-03/#SECURITY-3535"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/09/03/4"}],"affected":[{"package":{"name":"org.jenkins-ci.plugins:global-build-stats","ecosystem":"Maven","purl":"pkg:maven/org.jenkins-ci.plugins/global-build-stats"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"347.v32a"}]}],"versions":["1.1","1.2","1.3","1.4","1.5","244.v27c8a_2e50a_34","269.v214f74360b_3a_","282.v79ca_e079d1b_1","288.vb_2c4a_0f138b_b_","293.vd7b_d6e361475","304.ve03f19d5969e","307.v03dce5a_f8943","314.v2c5018728d76","316.vf8870f424d78","322.v22f4db_18e2dd"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-gm8g-fh49-qq6v/GHSA-gm8g-fh49-qq6v.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}