CVE-2025-41248 Affecting jenkins-2.504 package, versions *


Severity

Recommended
low

Based on default assessment until relevant scores are available.

Threat Intelligence

EPSS
0.05% (15th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-MINIMOSLATEST-JENKINS2504-13329121
  • published6 Oct 2025
  • disclosed16 Sept 2025

Introduced: 16 Sep 2025

NewCVE-2025-41248  (opens in a new tab)

How to fix?

There is no fixed version for Minimos:latest jenkins-2.504.

NVD Description

Note: Versions mentioned in the description apply only to the upstream jenkins-2.504 package and not the jenkins-2.504 package as distributed by Minimos. See How to fix? for Minimos:latest relevant fixed versions and status.

The Spring Security annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue when using @PreAuthorize and other method security annotations, resulting in an authorization bypass.

Your application may be affected by this if you are using Spring Security's @EnableMethodSecurity feature.

You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces.

This CVE is published in conjunction with CVE-2025-41249 https://spring.io/security/cve-2025-41249 .

CVSS Base Scores

version 3.1