CVE-2025-53661

Jenkins Testsigma Test Plan run Plugin 1.6 and earlier does not mask Testsigma API keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jenkins:testsigma_test_plan_run:*:*:*:*:*:jenkins:*:*

History

18 Jul 2025, 17:31

Type Values Removed Values Added
References () https://www.jenkins.io/security/advisory/2025-07-09/#SECURITY-3515 - () https://www.jenkins.io/security/advisory/2025-07-09/#SECURITY-3515 - Vendor Advisory
First Time Jenkins testsigma Test Plan Run
Jenkins
CPE cpe:2.3:a:jenkins:testsigma_test_plan_run:*:*:*:*:*:jenkins:*:*

10 Jul 2025, 13:17

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-09 16:15

Updated : 2025-07-18 17:31


NVD link : CVE-2025-53661

Mitre link : CVE-2025-53661

CVE.ORG link : CVE-2025-53661


JSON object : View

Products Affected

jenkins

  • testsigma_test_plan_run
CWE
CWE-522

Insufficiently Protected Credentials