PT-2025-11702 · Jenkins · Jenkins Zoho Qengine Plugin+1

Romuald Moisan

+1

·

Published

2025-03-19

·

Updated

2025-10-10

·

CVE-2025-30197

CVSS v3.1

3.1

Low

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Zoho QEngine Plugin versions 1.0.29.vfa cc23396502 and earlier
Description The issue concerns the Jenkins Zoho QEngine Plugin, where the QEngine API Key form field is not masked, potentially allowing attackers to observe and capture it.
Recommendations For Jenkins Zoho QEngine Plugin versions 1.0.29.vfa cc23396502 and earlier, consider masking the QEngine API Key form field to prevent potential attackers from observing and capturing it. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-30197
GHSA-2X3G-RR4W-4QRP

Affected Products

Jenkins
Jenkins Zoho Qengine Plugin