PT-2025-28923 · Jenkins · Jenkins Nouvola Divecloud Plugin+1

Romuald Moisan

·

Published

2025-07-09

·

Updated

2025-10-01

·

CVE-2025-53671

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Jenkins Nouvola DiveCloud Plugin versions 1.08 and earlier
Description: The Jenkins Nouvola DiveCloud Plugin does not mask DiveCloud API Keys and Credentials Encryption Keys displayed on the job configuration form, potentially allowing attackers to observe and capture them.
Recommendations: For versions prior to 1.08, ensure that DiveCloud API Keys and Credentials Encryption Keys are not exposed on the job configuration form.

Fix

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

BDU:2025-08569
CVE-2025-53671
GHSA-4V4V-92CX-X4F4

Affected Products

Jenkins
Jenkins Nouvola Divecloud Plugin