CVE-2025-31727
02.04.2025, 15:16
Jenkins AsakusaSatellite Plugin 0.1.1 and earlier stores AsakusaSatellite API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.Enginsight
Vendor | Product | Version |
---|---|---|
jenkins | asakusasatellite | 𝑥 ≤ 0.1.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration