PT-2025-28912 · Jenkins · Jenkins Qmetry Test Management Plugin+1

Said Abdesslem Messadi

·

Publicado

2025-07-09

·

Atualizado

2025-07-10

·

CVE-2025-53660

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Jenkins QMetry Test Management Plugin versions 1.13 and earlier
Description: The Jenkins QMetry Test Management Plugin does not properly protect Qmetry Automation API Keys. These keys are stored unencrypted in job config.xml files on the Jenkins controller and are visible to users with Item/Extended Read permission or file system access. The job configuration form also displays these API keys without masking, potentially allowing attackers to observe and capture them.
Recommendations: Versions prior to 1.13: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficiently Protected Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-08314
CVE-2025-53660
GHSA-962Q-84V8-HXHJ

Produtos afetados

Jenkins
Jenkins Qmetry Test Management Plugin