#VU117809 Insecure Default Initialization of Resource in Eggplant Runner - CVE-2025-64135
Published: October 30, 2025
Eggplant Runner
Jenkins
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the affected plugin sets the Java system property "jdk.http.auth.tunneling.disabledSchemes" to an empty value as part of applying a proxy configuration. A remote attacker can gain unauthorized access to sensitive information on the system.