Jenkins discloses project names via fingerprints
        
  High severity
        
          GitHub Reviewed
      
        Published
          May 13, 2022 
          to the GitHub Advisory Database
          •
          Updated Oct 22, 2025 
      
  
Package
Affected versions
< 1.625.2
      >= 1.626, < 1.638
  Patched versions
1.625.2
      1.638
  Description
        Published by the National Vulnerability Database
      Nov 25, 2015 
    
  
        Published to the GitHub Advisory Database
      May 13, 2022 
    
  
        Reviewed
      Feb 7, 2025 
    
  
        Last updated
      Oct 22, 2025 
    
  
The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain sensitive job and build name information via a direct request.
References