Description


Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses java.util.Random() which is not cryptographically secure for timing attack mitigation. This vulnerability is fixed in 2.2.

Related CPE's


Weaknesses



CWE-330

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.5 · High

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2026-01-13T20:16:07.673Z

1 week ago

Last modified

2026-01-20T17:36:48.247Z

10 hours ago