PT-2025-28923 · Jenkins · Jenkins Nouvola Divecloud Plugin+1
Romuald Moisan
·
Published
2025-07-09
·
Updated
2025-10-01
·
CVE-2025-53671
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Jenkins Nouvola DiveCloud Plugin versions 1.08 and earlier
Description:
The Jenkins Nouvola DiveCloud Plugin does not mask DiveCloud API Keys and Credentials Encryption Keys displayed on the job configuration form, potentially allowing attackers to observe and capture them.
Recommendations:
For versions prior to 1.08, ensure that DiveCloud API Keys and Credentials Encryption Keys are not exposed on the job configuration form.
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jenkins
Jenkins Nouvola Divecloud Plugin