Insecure Default Initialization of Resource in Eggplant Runner - CVE-2025-64135

 

Insecure Default Initialization of Resource in Eggplant Runner - CVE-2025-64135

Published: October 30, 2025


Vulnerability identifier: #VU117809
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2025-64135
CWE-ID: CWE-1188
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Jenkins
Affected software:
Eggplant Runner

Detailed vulnerability description

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to the affected plugin sets the Java system property "jdk.http.auth.tunneling.disabledSchemes" to an empty value as part of applying a proxy configuration. A remote attacker can gain unauthorized access to sensitive information on the system.


How to mitigate CVE-2025-64135

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

Sources