PT-2025-44296 · Jenkins · Jenkins Curseforge Publisher Plugin+1

Published

2025-10-29

·

Updated

2025-11-04

·

CVE-2025-64147

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Curseforge Publisher Plugin version 1.0
Description The Jenkins Curseforge Publisher Plugin version 1.0 does not mask API Keys displayed on the job configuration form. This increases the potential for attackers to observe and capture these keys. The API Keys are exposed on the job configuration form.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Fix

Missing Encryption of Sensitive Data

Weakness Enumeration

Related Identifiers

CVE-2025-64147
GHSA-HV42-CRPX-Q355

Affected Products

Jenkins
Jenkins Curseforge Publisher Plugin