Skip to main content

Vendor archive

samrocketman CVEs

Beta · best-effort

7 CVEs tagged to vendor samrocketman0 Critical, 6 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2025-68931

Published Jan 13, 2026

Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, AES/CBC/PKCS5Padding lacks authentication, making it vulnerable to padding orac…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-68925

Published Jan 13, 2026

Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, the code doesn't validate that the JWT header specifies "alg":"RS256". This vul…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-68704

Published Jan 13, 2026

Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses java.util.Random() which is not cryptographically secure for timing…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-68703

Published Jan 13, 2026

Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, the salt is derived from sha256Sum(passphrase). Two encryption operations with…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-68702

Published Jan 13, 2026

Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses padLeft(32, '0') when it should use padLeft(64, '0') because SHA-2…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-68701

Published Jan 13, 2026

Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses deterministic AES IV derivation from a passphrase. This vulnerabili…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-68698

Published Jan 13, 2026

Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses PKCS1Encoding which is vulnerable to Bleichenbacher padding oracle…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1