PT-2026-26076 · Jenkins · Jenkins Loadninja Plugin+1
Adam Jordan
+3
·
Published
2026-03-18
·
Updated
2026-03-21
·
CVE-2026-33004
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins LoadNinja Plugin versions 2.1 and earlier
Description
The Jenkins LoadNinja Plugin does not properly mask LoadNinja API keys as they are displayed on the job configuration form. This could allow attackers to observe and capture these keys.
Recommendations
Update to a newer version of the Jenkins LoadNinja Plugin that addresses this issue.
Fix
Information Disclosure
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jenkins
Jenkins Loadninja Plugin