4.3

CVSS3.1

CVE-2025-53665 -

Jenkins Apica Loadtest Plugin 1.10 and earlier does not mask Apica Loadtest LTP authentication tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

πŸ“… Published: July 9, 2025, 3:39 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

6.5

CVSS3.1

CVE-2025-53664 -

Jenkins Apica Loadtest Plugin 1.10 and earlier stores Apica Loadtest LTP authentication tokens unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.

πŸ“… Published: July 9, 2025, 3:39 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

6.5

CVSS3.1

CVE-2025-53663 -

Jenkins IBM Cloud DevOps Plugin 2.0.16 and earlier stores SonarQube authentication tokens unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.

πŸ“… Published: July 9, 2025, 3:39 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

6.5

CVSS3.1

CVE-2025-53662 -

Jenkins IFTTT Build Notifier Plugin 1.2 and earlier stores IFTTT Maker Channel Keys unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.

πŸ“… Published: July 9, 2025, 3:39 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

4.3

CVSS3.1

CVE-2025-53661 -

Jenkins Testsigma Test Plan run Plugin 1.6 and earlier does not mask Testsigma API keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

πŸ“… Published: July 9, 2025, 3:39 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

4.3

CVSS3.1

CVE-2025-53660 -

Jenkins QMetry Test Management Plugin 1.13 and earlier does not mask Qmetry Automation API Keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

πŸ“… Published: July 9, 2025, 3:39 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

6.5

CVSS3.1

CVE-2025-53659 -

Jenkins QMetry Test Management Plugin 1.13 and earlier stores Qmetry Automation API Keys unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.

πŸ“… Published: July 9, 2025, 3:39 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

5.4

CVSS3.1

CVE-2025-53658 -

Jenkins Applitools Eyes Plugin 1.16.5 and earlier does not escape the Applitools URL on the build page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

πŸ“… Published: July 9, 2025, 3:39 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

4.3

CVSS3.1

CVE-2025-53657 -

Jenkins ReadyAPI Functional Testing Plugin 1.11 and earlier does not mask SLM License Access Keys, client secrets, and passwords displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

πŸ“… Published: July 9, 2025, 3:39 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

6.5

CVSS3.1

CVE-2025-53656 -

Jenkins ReadyAPI Functional Testing Plugin 1.11 and earlier stores SLM License Access Keys, client secrets, and passwords unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file syst…

πŸ“… Published: July 9, 2025, 3:39 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.
Total resulsts: 349182
Page 4704 of 34,919
Β« previous page Β» next page
Filters