CVE Vulnerabilities

CVE-2025-31727

Missing Password Field Masking

Published: Apr 02, 2025 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Jenkins AsakusaSatellite Plugin 0.1.1 and earlier stores AsakusaSatellite API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.

Weakness

The product does not mask passwords during entry, increasing the potential for attackers to observe and capture passwords.

Potential Mitigations

References