PT-2025-50356 · Cloudbees+2 · Jenkins+1

James Nord

·

Published

2025-12-10

·

Updated

2025-12-23

·

CVE-2025-67638

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins versions 2.540 and earlier Jenkins LTS versions 2.528.2 and earlier
Description Jenkins does not mask build authorization tokens displayed on the job configuration form, potentially allowing attackers to observe and capture them.
Recommendations Update Jenkins to a version later than 2.540. Update Jenkins LTS to a version later than 2.528.2.

Fix

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

BDU:2025-15961
BIT-JENKINS-2025-67638
CVE-2025-67638
GHSA-HXJG-2JVF-H3RX

Affected Products

Jenkins
Red Os