CVE-2025-31723

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Apr 2, 2025
Updated: Apr 17, 2025
CWE ID 352

Summary

CVE-2025-31723 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Jenkins Simple Queue Plugin versions 1.4.6 and older. This issue enables unauthorized users to manipulate and alter the build queue order, potentially disrupting the normal flow of Jenkins jobs. An attacker could exploit this vulnerability by tricking a user into clicking a malicious link or form, allowing the attacker to execute unintended operations on the victim's Jenkins instance. To mitigate this risk, users are advised to update their Jenkins Simple Queue Plugin to the latest, non-vulnerable version.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share