NA - CVE-2025-53661 - Jenkins Testsigma Test Plan run Plugin 1.6 and...
Jenkins Testsigma Test Plan run Plugin 1.6 and earlier does not mask Testsigma API keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.
Jenkins IFTTT Build Notifier Plugin 1.2 and earlier stores IFTTT Maker Channel Keys unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with...
NA - CVE-2025-53663 - Jenkins IBM Cloud DevOps Plugin 2.0.16 and...
Jenkins IBM Cloud DevOps Plugin 2.0.16 and earlier stores SonarQube authentication tokens unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with...
NA - CVE-2025-53664 - Jenkins Apica Loadtest Plugin 1.10 and earlier...
Jenkins Apica Loadtest Plugin 1.10 and earlier stores Apica Loadtest LTP authentication tokens unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with...
NA - CVE-2025-53665 - Jenkins Apica Loadtest Plugin 1.10 and earlier...
Jenkins Apica Loadtest Plugin 1.10 and earlier does not mask Apica Loadtest LTP authentication tokens displayed on the job configuration form, increasing the potential for attackers to observe and...
NA - CVE-2025-53666 - Jenkins Dead Man's Snitch Plugin 0.1...
Jenkins Dead Man's Snitch Plugin 0.1 stores Dead Man's Snitch tokens unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended...
NA - CVE-2025-53667 - Jenkins Dead Man's Snitch Plugin 0.1 does...
Jenkins Dead Man's Snitch Plugin 0.1 does not mask Dead Man's Snitch tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.
NA - CVE-2025-53668 - Jenkins VAddy Plugin 1.2.8 and earlier stores...
Jenkins VAddy Plugin 1.2.8 and earlier stores Vaddy API Auth Keys unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission...
NA - CVE-2025-53669 - Jenkins VAddy Plugin 1.2.8 and earlier does not...
Jenkins VAddy Plugin 1.2.8 and earlier does not mask Vaddy API Auth Keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.
NA - CVE-2025-53670 - Jenkins Nouvola DiveCloud Plugin 1.08 and...
Jenkins Nouvola DiveCloud Plugin 1.08 and earlier stores DiveCloud API Keys and Credentials Encryption Keys unencrypted in job config.xml files on the Jenkins controller, where they can be viewed...