6.5

CVSS3.1

CVE-2025-53656 -

Jenkins ReadyAPI Functional Testing Plugin 1.11 and earlier stores SLM License Access Keys, client secrets, and passwords unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file syst…

πŸ“… Published: July 9, 2025, 3:39 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

5.3

CVSS3.1

CVE-2025-53655 -

Jenkins Statistics Gatherer Plugin 2.0.3 and earlier does not mask the AWS Secret Key on the global configuration form, increasing the potential for attackers to observe and capture it.

πŸ“… Published: July 9, 2025, 3:39 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

6.5

CVSS3.1

CVE-2025-53654 -

Jenkins Statistics Gatherer Plugin 2.0.3 and earlier stores the AWS Secret Key unencrypted in its global configuration file on the Jenkins controller, where it can be viewed by users with access to the Jenkins controller file system.

πŸ“… Published: July 9, 2025, 3:39 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

4.3

CVSS3.1

CVE-2025-53653 -

Jenkins Aqua Security Scanner Plugin 3.2.8 and earlier stores Scanner Tokens for Aqua API unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.

πŸ“… Published: July 9, 2025, 3:39 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

8.2

CVSS3.1

CVE-2025-53652 -

Jenkins Git Parameter Plugin 439.vb_0e46ca_14534 and earlier does not validate that the Git parameter value submitted to the build matches one of the offered choices, allowing attackers with Item/Build permission to inject arbitrary values into Git parameters.

πŸ“… Published: July 9, 2025, 3:39 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

6.3

CVSS3.1

CVE-2025-53651 -

Jenkins HTML Publisher Plugin 425 and earlier displays log messages that include the absolute paths of files archived during the Publish HTML reports post-build step, exposing information about the Jenkins controller file system in the build log.

πŸ“… Published: July 9, 2025, 3:39 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

7.3

CVSS3.1

CVE-2025-53650 -

Jenkins Credentials Binding Plugin 687.v619cb_15e923f and earlier does not properly mask (i.e., replace with asterisks) credentials present in exception error messages that are written to the build log.

πŸ“… Published: July 9, 2025, 3:39 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

5.3

CVSS3.1

CVE-2025-7381 - Exposure of sensitive PHP information to an unauthorized control sphere in mautic/mautic images

ImpactThis is an information disclosure vulnerability originating from PHP's base image. This vulnerability exposes the PHP version through an X-Powered-By header, which attackers could exploit to fingerprint the server and identify potential weaknesses. WorkaroundsThe mitigation requires changing…

πŸ“… Published: July 9, 2025, 3:16 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-7204 - Exposure of password hashes via API responses in ConnectWise PSA

In ConnectWise PSA versions older than 2025.9, a vulnerability exists where authenticated users could gain access to sensitive user information. Specific API requests were found to return an overly verbose user object, which included encrypted password hashes for other users. Authenticated users co…

πŸ“… Published: July 9, 2025, 2:50 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 7:53 p.m.

4.3

CVSS3.1

CVE-2025-1112 - IBM OpenPages with Watson information disclosure

IBM OpenPages with Watson 8.3 and 9.0 could allow an authenticated user to obtain sensitive information that should only be available to privileged users.

πŸ“… Published: July 9, 2025, 2:33 p.m. πŸ”„ Last Modified: Aug. 24, 2025, 11:20 a.m.
Total resulsts: 347933
Page 4580 of 34,794
Β« previous page Β» next page
Filters