CVE-2025-58459: Jenkins global-build-stats Plugin missing permission check can result in graph IDs being enumerated
Jenkins global-build-stats Plugin 322.v22f4db_18e2dd and earlier does not perform permission checks in its REST API endpoints, allowing attackers with Overall/Read permission to enumerate graph IDs.
This has been patched in version 347.v32a_eb_0493c4f.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-58459 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →