CVE-2025-64140
Jenkins Azure CLI Plugin 0.9 and earlier does not restrict which commands it executes on the Jenkins controller.
This allows attackers with Item/Configure permission to execute arbitrary shell commands on the Jenkins controller.
As of publication of this advisory, there is no fix.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://nvd.nist.gov/vuln/detail/CVE-2025-64140, https://github.com/jenkinsci/azure-cli-plugin, https://www.jenkins.io/security/advisory/2025-10-29/#SECURITY-3538, http://www.openwall.com/lists/oss-security/2025/10/29/2
