Missing Authorization Affecting org.jenkins-ci.plugins:nexus-task-runner package, versions [0,]


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Missing Authorization vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JAVA-ORGJENKINSCIPLUGINS-13776172
  • published30 Oct 2025
  • disclosed29 Oct 2025
  • creditAris ISSAD

Introduced: 29 Oct 2025

NewCVE-2025-64142  (opens in a new tab)
CWE-862  (opens in a new tab)

How to fix?

There is no fixed version for org.jenkins-ci.plugins:nexus-task-runner.

Overview

org.jenkins-ci.plugins:nexus-task-runner is a This plugin executes Sonatype Nexus scheduled tasks after your build.

For example, if you want to refresh your Nexus's repositories index after building your project, you can use execute a Nexus task whose type is "Publish index" using this plugin.

Affected versions of this package are vulnerable to Missing Authorization via the HTTP endpoint. An attacker with Overall/Read permission can cause unauthorized connections to arbitrary URLs with attacker-controlled credentials by sending crafted requests.

CVSS Base Scores

version 4.0
version 3.1