PT-2025-28909 · Jenkins · Jenkins Readyapi Functional Testing Plugin+1
Romuald Moisan
+1
·
Published
2025-07-09
·
Updated
2025-07-10
·
CVE-2025-53657
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Jenkins ReadyAPI Functional Testing Plugin versions 1.11 and earlier
Description:
The Jenkins ReadyAPI Functional Testing Plugin does not properly mask sensitive information such as SLM License Access Keys, client secrets, and passwords on the job configuration form. This increases the risk of unauthorized observation and capture of these credentials.
Recommendations:
Upgrade to Jenkins ReadyAPI Functional Testing Plugin version 1.12 or later.
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins
Jenkins Readyapi Functional Testing Plugin