MEDIUM✓ PATCH🇵🇱 Wersja polska

CVE-2025-31728

CVSS 5.5v3.1pub. 2025-04-02upd. 2025-04-17

Jenkins AsakusaSatellite Plugin 0.1.1 and earlier does not mask AsakusaSatellite API keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
  • Jenkins Asakusasatellite

    APP
    Jenkins
    ≤ 0.1.1
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
CI/CD
CWE
References

Related vulnerabilities

CVE-2025-31727MEDIUM5.5same product

Jenkins AsakusaSatellite Plugin 0.1.1 and earlier stores AsakusaSatellite API keys unencrypted in job config.x...

CVE-2024-23897CRITICAL9.8⚠ KEVPL ✓same vendor

Jenkins CLI – odczyt dowolnych plików przez path traversal bez uwierzytelnienia

CVE-2019-1003030CRITICAL9.9⚠ KEVPL ✓same vendor

Jenkins Pipeline Groovy Plugin — bypass sandbox i wykonanie kodu (RCE)

CVE-2019-1003029CRITICAL9.9⚠ KEVPL ✓same vendor

Jenkins Script Security Plugin — sandbox bypass umożliwiający RCE

CVE-2018-1000861CRITICAL9.8⚠ KEVPL ✓same vendor

RCE w Jenkins — nieuprawnione wywołanie metod przez Stapler framework