{"id":"GHSA-mrpq-9jr3-rqq9","summary":"Jenkins MCP Server Plugin does not perform permission checks in multiple MCP tools","details":"Jenkins MCP Server Plugin 0.84.v50ca_24ef83f2 and earlier does not perform permission checks in several MCP tools.\n\nThis allows to do the following:\n\n- Attackers with Item/Read permission can obtain information about the configured SCM in a job despite lacking Item/Extended Read permission (`getJobScm`).\n\n- Attackers with Item/Read permission can trigger new builds of a job despite lacking Item/Build permission (`triggerBuild`).\n\n- Attackers without Overall/Read permission can retrieve the names of configured clouds (`getStatus`).\n\nMCP Server Plugin 0.86.v7d3355e6a_a_18 performs permission checks for the affected MCP tools.","aliases":["CVE-2025-64132"],"modified":"2025-11-05T21:07:53.091701Z","published":"2025-10-29T15:31:56Z","database_specific":{"nvd_published_at":"2025-10-29T14:15:57Z","cwe_ids":["CWE-862"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2025-10-29T18:52:20Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-64132"},{"type":"WEB","url":"https://github.com/jenkinsci/mcp-server-plugin/commit/59de6a268b4c6844a3a9c6c55a541de183e71a97"},{"type":"PACKAGE","url":"https://github.com/jenkinsci/mcp-server-plugin"},{"type":"WEB","url":"https://www.jenkins.io/security/advisory/2025-10-29/#SECURITY-3622"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/10/29/2"}],"affected":[{"package":{"name":"io.jenkins.plugins:mcp-server","ecosystem":"Maven","purl":"pkg:maven/io.jenkins.plugins/mcp-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.86.v7d3355e6a"}]}],"versions":["0.16.vc9132432728d","0.17.v941ed9da_c023","0.25.v59ca_c2d5ffc5","0.26.v4a_0d810a_7f71","0.27.v4034b_d4c4cb_5","0.33.vecd845512255","0.34.v9f214cb_76168","0.35.v03801a_87ff6d","0.37.v5d2d8c089e8b_","0.41.vdd84b_1430491","0.46.v43ff45cf7fe5","0.57.vc17d46a_5d10b_","0.77.veb_c7b_a_b_f0445","0.84.v50ca_24ef83f2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-mrpq-9jr3-rqq9/GHSA-mrpq-9jr3-rqq9.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"}]}