CVE-2025-31727
Essential information
- Published
- 02/04/2025 15:16
- Modified
- 02/04/2025 15:16
- Author
- —
- Creator
- —
- CISA KEV
- No
- CWE
- —
- CVSS vector
- — — —
Description
Jenkins AsakusaSatellite Plugin 0.1.1 and earlier stores AsakusaSatellite API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.
NVD status
- Status
- Received — CVE has been recently published to the CVE List and has been received by the NVD.
- Source
- [email protected]
- NVD
- View on NVD
Affected products (CPE)
| Product | CPE |
|---|---|
| jenkins / asakusa satellite plugin | cpe:2.3:a:jenkins:asakusa_satellite_plugin:<0.1.1:*:*:*:*:*:*:* |