PT-2025-14516 · Jenkins · Jenkins Stack Hammer Plugin+1
Romuald Moisan
+1
·
Published
2025-04-02
·
Updated
2025-04-17
·
CVE-2025-31726
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Jenkins Stack Hammer Plugin versions 1.0.6 and earlier
Description
The issue concerns the storage of Stack Hammer API keys in an unencrypted manner within job config.xml files on the Jenkins controller. This allows users with Extended Read permission or access to the Jenkins controller file system to view these keys.
Recommendations
For Jenkins Stack Hammer Plugin versions 1.0.6 and earlier, consider restricting access to the Jenkins controller file system and limiting Extended Read permissions to minimize exposure of the unencrypted Stack Hammer API keys until a fix is available.
Fix
Improper Access Control
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jenkins
Jenkins Stack Hammer Plugin