HomeDefault status
affected
2.541 (maven) before *
unaffected
2.528.3 (maven) before 2.528.*
unaffected
Description
A cross-site request forgery (CSRF) vulnerability in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier allows attackers to trick users into logging in to the attacker's account.
Product status
2.541 (maven) before *
2.528.3 (maven) before 2.528.*
References
www.jenkins.io/security/advisory/2025-12-10/ (Jenkins Security Advisory 2025-12-10)