PT-2025-28921 · Jenkins · Jenkins Vaddy Plugin+1

Romuald Moisan

+1

·

Published

2025-07-09

·

Updated

2025-07-10

·

CVE-2025-53669

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Name of the Vulnerable Software and Affected Versions:

Jenkins VAddy Plugin versions 1.2.8 and earlier

Description:

The Jenkins VAddy Plugin does not mask Vaddy API Auth Keys displayed on the job configuration form, potentially allowing attackers to observe and capture them.

Recommendations:

Update to a newer version of the Jenkins VAddy Plugin to address this issue.

Fix

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

BDU:2025-08317
CVE-2025-53669
GHSA-8GP3-M447-GW2V

Affected Products

Jenkins
Jenkins Vaddy Plugin