CVE-2025-24402: Jenkins Azure Service Fabric

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

A cross-site request forgery (CSRF) vulnerability in Jenkins Azure Service Fabric Plugin 1.6 and earlier allows attackers to connect to a Service Fabric URL using attacker-specified credentials IDs obtained through another method.

Affected products

  • Jenkins Azure Service Fabric: up to and including 1.6

Published 2025-01-22. Last modified 2026-06-17.