PT-2025-14517 · Jenkins · Jenkins Asakusasatellite Plugin+1

Romuald Moisan

+1

·

Published

2025-04-02

·

Updated

2025-04-17

·

CVE-2025-31727

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Jenkins AsakusaSatellite Plugin versions 0.1.1 and earlier
Description The issue concerns the storage of AsakusaSatellite API keys in an unencrypted manner within job config.xml files on the Jenkins controller. This allows users with Item/Extended Read permission or access to the Jenkins controller file system to view these keys.
Recommendations For Jenkins AsakusaSatellite Plugin versions 0.1.1 and earlier, consider restricting access to the Jenkins controller file system and limiting Item/Extended Read permissions to minimize exposure of the unencrypted AsakusaSatellite API keys until a fix is available.

Fix

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

BDU:2025-03849
CVE-2025-31727
GHSA-FV9Q-FQ62-C6QG

Affected Products

Jenkins
Jenkins Asakusasatellite Plugin