PT-2025-14516 · Jenkins · Jenkins Stack Hammer Plugin+1

Romuald Moisan

+1

·

Published

2025-04-02

·

Updated

2025-04-17

·

CVE-2025-31726

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Jenkins Stack Hammer Plugin versions 1.0.6 and earlier
Description The issue concerns the storage of Stack Hammer API keys in an unencrypted manner within job config.xml files on the Jenkins controller. This allows users with Extended Read permission or access to the Jenkins controller file system to view these keys.
Recommendations For Jenkins Stack Hammer Plugin versions 1.0.6 and earlier, consider restricting access to the Jenkins controller file system and limiting Extended Read permissions to minimize exposure of the unencrypted Stack Hammer API keys until a fix is available.

Fix

Improper Access Control

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

BDU:2025-03822
CVE-2025-31726
GHSA-2WXQ-944J-5G2V

Affected Products

Jenkins
Jenkins Stack Hammer Plugin