CVE-2025-64135EPSS p23.3%
CVE-2025-64135CVE-2025-64135
jenkins / eggplant_runner
Description
Jenkins Eggplant Runner Plugin 0.0.1.301.v963cffe8ddb_8 and earlier sets the Java system property `jdk.http.auth.tunneling.disabledSchemes` to an empty value, disabling a protection mechanism of the Java runtime.
Scoring
| CVSS | 5.9 () |
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 0.32% probability of exploitation · percentile 23.3% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-08 |