CVE-2025-64135: Jenkins Eggplant Runner Plugin protection mechanism disabled
(updated )
Jenkins Eggplant Runner Plugin 0.0.1.301.v963cffe8ddb_8 and earlier sets the Java system property jdk.http.auth.tunneling.disabledSchemes to an empty value as part of applying a proxy configuration.
This disables a protection mechanism of the Java runtime addressing CVE-2016-5597.
As of publication of this advisory, there is no fix.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-64135 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →