PT-2025-28908 · Jenkins · Jenkins Readyapi Functional Testing Plugin+1
Romuald Moisan
+1
·
Published
2025-07-09
·
Updated
2025-07-18
·
CVE-2025-53656
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Jenkins ReadyAPI Functional Testing Plugin versions 1.11 and earlier
Description:
The Jenkins ReadyAPI Functional Testing Plugin stores sensitive information, including SLM License Access Keys, client secrets, and passwords, in unencrypted format within job config.xml files on the Jenkins controller. This allows users with Item/Extended Read permission or file system access to view these credentials.
Recommendations:
Versions prior to 1.11: Ensure that access to the Jenkins controller file system is restricted to authorized personnel only. Limit Item/Extended Read permissions to only those users who require access to job configurations.
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jenkins
Jenkins Readyapi Functional Testing Plugin