PT-2025-14518 · Jenkins · Jenkins Asakusasatellite Plugin+1

Published

2025-04-02

·

Updated

2025-04-02

·

CVE-2025-31728

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Jenkins AsakusaSatellite Plugin versions 0.1.1 and earlier
Description The issue concerns the exposure of AsakusaSatellite API keys on the job configuration form, which could allow attackers to observe and capture them.
Recommendations For Jenkins AsakusaSatellite Plugin versions 0.1.1 and earlier, consider masking AsakusaSatellite API keys displayed on the job configuration form to prevent potential attackers from observing and capturing them. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Encryption of Sensitive Data

Weakness Enumeration

Related Identifiers

BDU:2025-03847
CVE-2025-31728
GHSA-M254-F6H4-P93G

Affected Products

Jenkins
Jenkins Asakusasatellite Plugin