Skip to content

[GHSA-wfhp-qgm8-5p5c] Jenkins has a build information disclosure vulnerability through Run Parameter #7067

Merged
advisory-database[bot] merged 1 commit intoBruceliu-rs/advisory-improvement-7067from
Bruceliu-rs-GHSA-wfhp-qgm8-5p5c
Feb 25, 2026
Merged

[GHSA-wfhp-qgm8-5p5c] Jenkins has a build information disclosure vulnerability through Run Parameter #7067
advisory-database[bot] merged 1 commit intoBruceliu-rs/advisory-improvement-7067from
Bruceliu-rs-GHSA-wfhp-qgm8-5p5c

Conversation

@Bruceliu-rs
Copy link

Updates

  • Affected products

Comments
The current affected range does not account for the Jenkins LTS release track. Jenkins LTS 2.541.2 contains the fix for this vulnerability (see https://www.jenkins.io/security/advisory/2026-02-18/). The NVD CPE data correctly separates the LTS and weekly ranges (see https://nvd.nist.gov/vuln/detail/CVE-2026-27100). The affected range should be split into two ranges: < 2.541.2 (covering all versions before the LTS fix) and >= 2.542, < 2.551 (covering unfixed weekly versions), so that LTS 2.541.2 is correctly recognized as patched.

@github-actions github-actions bot changed the base branch from main to Bruceliu-rs/advisory-improvement-7067 February 25, 2026 08:25
@advisory-database advisory-database bot merged commit 2083b80 into Bruceliu-rs/advisory-improvement-7067 Feb 25, 2026
4 checks passed
@advisory-database
Copy link
Contributor

Hi @Bruceliu-rs! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

@advisory-database advisory-database bot deleted the Bruceliu-rs-GHSA-wfhp-qgm8-5p5c branch February 25, 2026 20:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant