CVE-2025-67639: Jenkins has a CSRF vulnerability on the login form
A cross-site request forgery (CSRF) vulnerability in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier allows attackers to trick users into logging in to the attacker’s account.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-67639 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →