MEDIUM4.3
GHSA-g28p-6mcc-v4rv
Jenkins exposes other users' timezone and view names to users with Overall/Read permission
Quick fix
GHSA-g28p-6mcc-v4rv — org.jenkins-ci.main:jenkins-core: upgrade to the fixed version with the command below.
# pom.xml: bump <version>2.555.3</version> for org.jenkins-ci.main:jenkins-coreDetails
Missing permission checks in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allow attackers with Overall/Read permission to determine other users' configured timezone and to enumerate view names of other users' "My Views".
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.jenkins-ci.main:jenkins-core
Introduced in:
0Fixed in: 2.555.3Fix
# pom.xml: bump <version>2.555.3</version> for org.jenkins-ci.main:jenkins-coreMaven/org.jenkins-ci.main:jenkins-core
Introduced in:
2.556Fixed in: 2.568Fix
# pom.xml: bump <version>2.568</version> for org.jenkins-ci.main:jenkins-coreReferences
- https://nvd.nist.gov/vuln/detail/CVE-2026-53439[ADVISORY]
- https://github.com/jenkinsci/jenkins/commit/0586de425598497cfb4dcdafa5007e507a440a77[WEB]
- https://github.com/jenkinsci/jenkins/commit/98fe05f1753f664ffddd295a03492684b74e1950[WEB]
- https://github.com/jenkinsci/jenkins[PACKAGE]
- https://www.jenkins.io/security/advisory/2026-06-10/#SECURITY-3713[WEB]