PT-2025-28908 · Jenkins · Jenkins Readyapi Functional Testing Plugin+1

Romuald Moisan

+1

·

Published

2025-07-09

·

Updated

2025-07-18

·

CVE-2025-53656

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Jenkins ReadyAPI Functional Testing Plugin versions 1.11 and earlier
Description: The Jenkins ReadyAPI Functional Testing Plugin stores sensitive information, including SLM License Access Keys, client secrets, and passwords, in unencrypted format within job config.xml files on the Jenkins controller. This allows users with Item/Extended Read permission or file system access to view these credentials.
Recommendations: Versions prior to 1.11: Ensure that access to the Jenkins controller file system is restricted to authorized personnel only. Limit Item/Extended Read permissions to only those users who require access to job configurations.

Fix

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

BDU:2025-08322
CVE-2025-53656
GHSA-884F-P57J-F258

Affected Products

Jenkins
Jenkins Readyapi Functional Testing Plugin