CVE-2025-31728

Jenkins AsakusaSatellite Plugin 0.1.1 and earlier does not mask AsakusaSatellite API keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jenkins:asakusasatellite:*:*:*:*:*:jenkins:*:*

History

17 Apr 2025, 14:35

Type Values Removed Values Added
CPE cpe:2.3:a:jenkins:asakusasatellite:*:*:*:*:*:jenkins:*:*
References () https://www.jenkins.io/security/advisory/2025-04-02/#SECURITY-3523 - () https://www.jenkins.io/security/advisory/2025-04-02/#SECURITY-3523 - Vendor Advisory
First Time Jenkins
Jenkins asakusasatellite

03 Apr 2025, 21:15

Type Values Removed Values Added
Summary
  • (es) Jenkins AsakusaSatellite Plugin 0.1.1 y versiones anteriores no enmascaran las claves de API de AsakusaSatellite que se muestran en el formulario de configuración del trabajo, lo que aumenta la posibilidad de que los atacantes las observen y capturen.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CWE CWE-549

02 Apr 2025, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-02 15:16

Updated : 2025-04-17 14:35


NVD link : CVE-2025-31728

Mitre link : CVE-2025-31728

CVE.ORG link : CVE-2025-31728


JSON object : View

Products Affected

jenkins

  • asakusasatellite
CWE
CWE-549

Missing Password Field Masking