Jenkins Sensedia Api Platform tools Plugin 1.0 stores the Sensedia API Manager integration token unencrypted in its global configuration file on the Jenkins controller, where it can be viewed by users with access to the Jenkins controller file system.
References
| Link | Resource |
|---|---|
| https://www.jenkins.io/security/advisory/2025-07-09/#SECURITY-3551 | Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2025/07/09/4 |
Configurations
History
No history.
Information
Published : 2025-07-09 16:15
Updated : 2025-11-04 22:16
NVD link : CVE-2025-53673
Mitre link : CVE-2025-53673
CVE.ORG link : CVE-2025-53673
JSON object : View
Products Affected
jenkins
- sensedia_api_platform_tools
CWE
CWE-311
Missing Encryption of Sensitive Data
