5.5
CVE-2025-31728
- EPSS 0.02%
- Veröffentlicht 02.04.2025 15:16:00
- Zuletzt bearbeitet 17.04.2025 14:35:36
- Quelle jenkinsci-cert@googlegroups.co
- Teams Watchlist Login
- Unerledigt Login
Jenkins AsakusaSatellite Plugin 0.1.1 and earlier does not mask AsakusaSatellite API keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Jenkins ≫ Asakusasatellite SwPlatformjenkins Version <= 0.1.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.02% | 0.047 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
134c704f-9b21-4f2e-91b3-4a467353bcc0 | 5.5 | 2.1 | 3.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
|
CWE-549 Missing Password Field Masking
The product does not mask passwords during entry, increasing the potential for attackers to observe and capture passwords.