PT-2025-44293 · Jenkins · Jenkins Byteguard Build Actions Plugin+1

Published

2025-10-29

·

Updated

2025-11-04

·

CVE-2025-64144

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins ByteGuard Build Actions Plugin version 1.0
Description The Jenkins ByteGuard Build Actions Plugin version 1.0 stores API tokens unencrypted in config.xml files on the Jenkins controller. These files are accessible to users with Item/Extended Read permission, or those with access to the Jenkins controller file system. This allows unauthorized viewing of the API tokens.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Encryption of Sensitive Data

Weakness Enumeration

Related Identifiers

CVE-2025-64144
GHSA-2VMR-8C82-X8XQ

Affected Products

Jenkins
Jenkins Byteguard Build Actions Plugin