CVE-2025-58459: Jenkins Global Build Stats
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Jenkins global-build-stats Plugin 322.v22f4db_18e2dd and earlier does not perform permission checks in its REST API endpoints, allowing attackers with Overall/Read permission to enumerate graph IDs.
Affected products
- Jenkins Global Build Stats: up to and including 322.v22f4db_18e2dd
Published 2025-09-03. Last modified 2026-06-17.