PT-2025-28907 · Jenkins · Jenkins Statistics Gatherer Plugin+1

Romuald Moisan

·

Published

2025-07-09

·

Updated

2025-07-18

·

CVE-2025-53655

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Jenkins Statistics Gatherer Plugin versions 2.0.3 and earlier
Description: The Jenkins Statistics Gatherer Plugin does not mask the AWS Secret Key on the global configuration form and stores it unencrypted in the org.jenkins.plugins.statistics.gatherer.StatisticsConfiguration.xml configuration file on the Jenkins controller. This allows users with access to the Jenkins controller file system to view the key, and increases the potential for attackers to observe and capture it.
Recommendations: For versions prior to 2.0.3, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2025-08321
CVE-2025-53655
GHSA-26X3-7JW5-7MG4

Affected Products

Jenkins
Jenkins Statistics Gatherer Plugin