Jenkins Eggplant Runner Plugin 0.0.1.301.v963cffe8ddb_8 and earlier sets the Java system property `jdk.http.auth.tunneling.disabledSchemes` to an empty value, disabling a protection mechanism of the Java runtime.

Subscriptions

Vendors Products
Jenkins Subscribe
Eggplant Subscribe
Eggplant Runner Subscribe
Jenkins Subscribe

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-w5r3-gr8w-7fj5 Jenkins Eggplant Runner Plugin protection mechanism disabled
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 22 Dec 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins eggplant Runner
CPEs cpe:2.3:a:jenkins:eggplant_runner:*:*:*:*:*:jenkins:*:*
Vendors & Products Jenkins eggplant Runner

Tue, 04 Nov 2025 22:30:00 +0000

Type Values Removed Values Added
References

Thu, 30 Oct 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins
Jenkins eggplant
Jenkins jenkins
Vendors & Products Jenkins
Jenkins eggplant
Jenkins jenkins

Wed, 29 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1188
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 29 Oct 2025 13:45:00 +0000

Type Values Removed Values Added
Description Jenkins Eggplant Runner Plugin 0.0.1.301.v963cffe8ddb_8 and earlier sets the Java system property `jdk.http.auth.tunneling.disabledSchemes` to an empty value, disabling a protection mechanism of the Java runtime.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2025-11-04T21:14:27.669Z

Reserved: 2025-10-28T07:34:37.542Z

Link: CVE-2025-64135

cve-icon Vulnrichment

Updated: 2025-11-04T21:14:27.669Z

cve-icon NVD

Status : Analyzed

Published: 2025-10-29T14:15:57.773

Modified: 2025-12-22T15:23:37.557

Link: CVE-2025-64135

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-30T14:38:29Z

Weaknesses