5.5
CVE-2025-31728
- EPSS 0.02%
- Published 02.04.2025 15:16:00
- Last modified 17.04.2025 14:35:36
- Source jenkinsci-cert@googlegroups.co
- Teams watchlist Login
- Open Login
Jenkins AsakusaSatellite Plugin 0.1.1 and earlier does not mask AsakusaSatellite API keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.
Data is provided by the National Vulnerability Database (NVD)
Jenkins ≫ Asakusasatellite SwPlatformjenkins Version <= 0.1.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.02% | 0.047 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
134c704f-9b21-4f2e-91b3-4a467353bcc0 | 5.5 | 2.1 | 3.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
|
CWE-549 Missing Password Field Masking
The product does not mask passwords during entry, increasing the potential for attackers to observe and capture passwords.