CVE-2025-58459: Jenkins Global Build Stats

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Jenkins global-build-stats Plugin 322.v22f4db_18e2dd and earlier does not perform permission checks in its REST API endpoints, allowing attackers with Overall/Read permission to enumerate graph IDs.

Affected products

  • Jenkins Global Build Stats: up to and including 322.v22f4db_18e2dd

Published 2025-09-03. Last modified 2026-06-17.