PT-2025-28923 · Jenkins · Jenkins Nouvola Divecloud Plugin+1

·

CVE-2025-53671

·

Published

2025-07-09

·

Updated

2025-10-01

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Jenkins Nouvola DiveCloud Plugin versions 1.08 and earlier
Description: The Jenkins Nouvola DiveCloud Plugin does not mask DiveCloud API Keys and Credentials Encryption Keys displayed on the job configuration form, potentially allowing attackers to observe and capture them.
Recommendations: For versions prior to 1.08, ensure that DiveCloud API Keys and Credentials Encryption Keys are not exposed on the job configuration form.

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-08569
CVE-2025-53671
GHSA-4V4V-92CX-X4F4

Affected Products

Jenkins
Jenkins Nouvola Divecloud Plugin