CVE Vulnerabilities

CVE-2025-31728

Missing Password Field Masking

Published: Apr 02, 2025 | Modified: Apr 17, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Jenkins AsakusaSatellite Plugin 0.1.1 and earlier does not mask AsakusaSatellite API keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

Weakness

The product does not mask passwords during entry, increasing the potential for attackers to observe and capture passwords.

Affected Software

NameVendorStart VersionEnd Version
AsakusasatelliteJenkins*0.1.1 (including)

Potential Mitigations

References