MEDIUM 4.3
GHSA-g28p-6mcc-v4rv
Jenkins exposes other users' timezone and view names to users with Overall/Read permission
Quick fix
GHSA-g28p-6mcc-v4rv — org.jenkins-ci.main:jenkins-core: upgrade to the fixed version with the command below.
# pom.xml: bump <version>2.555.3</version> for org.jenkins-ci.main:jenkins-core Details
Missing permission checks in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allow attackers with Overall/Read permission to determine other users' configured timezone and to enumerate view names of other users' "My Views".
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven / org.jenkins-ci.main:jenkins-core
Introduced in:
0 Fixed in: 2.555.3 Fix
# pom.xml: bump <version>2.555.3</version> for org.jenkins-ci.main:jenkins-core Maven / org.jenkins-ci.main:jenkins-core
Introduced in:
2.556 Fixed in: 2.568 Fix
# pom.xml: bump <version>2.568</version> for org.jenkins-ci.main:jenkins-core References
- https://nvd.nist.gov/vuln/detail/CVE-2026-53439 [ADVISORY]
- https://github.com/jenkinsci/jenkins/commit/0586de425598497cfb4dcdafa5007e507a440a77 [WEB]
- https://github.com/jenkinsci/jenkins/commit/98fe05f1753f664ffddd295a03492684b74e1950 [WEB]
- https://github.com/jenkinsci/jenkins [PACKAGE]
- https://www.jenkins.io/security/advisory/2026-06-10/#SECURITY-3713 [WEB]