Jenkins ReadyAPI Functional Testing Plugin 1.11 and earlier stores SLM License Access Keys, client secrets, and passwords unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.
References
Link | Resource |
---|---|
https://www.jenkins.io/security/advisory/2025-07-09/#SECURITY-3556 | Vendor Advisory |
Configurations
History
18 Jul 2025, 17:33
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:jenkins:readyapi_functional_testing:*:*:*:*:*:jenkins:*:* | |
First Time |
Jenkins
Jenkins readyapi Functional Testing |
|
References | () https://www.jenkins.io/security/advisory/2025-07-09/#SECURITY-3556 - Vendor Advisory |
10 Jul 2025, 13:17
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-07-09 16:15
Updated : 2025-07-18 17:33
NVD link : CVE-2025-53656
Mitre link : CVE-2025-53656
CVE.ORG link : CVE-2025-53656
JSON object : View
Products Affected
jenkins
- readyapi_functional_testing
CWE
CWE-256
Plaintext Storage of a Password