ZeroHour

CVE-2025-53669

CVSS 3.1
4.3 medium
EPSS
<1%p14
Published
()
Modified
Description

Jenkins VAddy Plugin 1.2.8 and earlier does not mask Vaddy API Auth Keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

Vendors
jenkins
Products
vaddy
Weakness
CWE-256, CWE-522
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.