PT-2025-3757 · Zoom · Zoom Jenkins Marketplace Plugin

Published

2025-02-03

·

Updated

2025-02-26

·

CVE-2025-0148

CVSS v3.1

2.6

Low

VectorAV:A/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Zoom Jenkins Marketplace plugin version 1.6 and earlier
Description The issue concerns missing password field masking in the Zoom Jenkins Marketplace plugin, which may allow an unauthenticated user to conduct a disclosure of information via adjacent network access.
Recommendations For Zoom Jenkins Marketplace plugin version 1.6 and earlier, update to version 1.6 or later to resolve the issue.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-0148
GHSA-4352-JXWG-88RM

Affected Products

Zoom Jenkins Marketplace Plugin