ZeroHour

CVE-2025-67638

CVSS 3.1
4.3 medium
EPSS
<1%p5
Published
()
Modified
Description

Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not mask build authorization tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

Vendors
jenkins
Products
jenkins
Weakness
CWE-312
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.