Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Jervis HIGH 7.5
CVE-2025-68698

Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses PKCS1Encoding which is vulnerable to …

Fix: 2.2+
Fix from $1,950 2026-01-13
Jervis HIGH 7.5
CVE-2025-68701

Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses deterministic AES IV derivation from …

Fix: 2.2+
Fix from $1,950 2026-01-13
Jervis HIGH 7.5
CVE-2025-68702

Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses padLeft(32, '0') when it should use …

Fix: 2.2+
Fix from $1,950 2026-01-13
Jervis HIGH 7.5
CVE-2025-68703

Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, the salt is derived from sha256Sum(passphrase). T…

Fix: 2.2+
Fix from $1,950 2026-01-13
Jervis HIGH 7.5
CVE-2025-68704

Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses java.util.Random() which is not crypt…

Fix: 2.2+
Fix from $1,950 2026-01-13
Jervis HIGH 7.5
CVE-2025-68931

Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, AES/CBC/PKCS5Padding lacks authentication, making…

Fix: 2.2+
Fix from $1,950 2026-01-13
Jervis MEDIUM 5.3
CVE-2025-68925

Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, the code doesn't validate that the JWT header spe…

Fix: 2.2+
Fix from $1,600 2026-01-13