PT-2025-14518 · Jenkins · Jenkins Asakusasatellite Plugin+1
Published
2025-04-02
·
Updated
2025-04-02
·
CVE-2025-31728
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Jenkins AsakusaSatellite Plugin versions 0.1.1 and earlier
Description
The issue concerns the exposure of AsakusaSatellite API keys on the job configuration form, which could allow attackers to observe and capture them.
Recommendations
For Jenkins AsakusaSatellite Plugin versions 0.1.1 and earlier, consider masking AsakusaSatellite API keys displayed on the job configuration form to prevent potential attackers from observing and capturing them.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Encryption of Sensitive Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jenkins
Jenkins Asakusasatellite Plugin