CVE-2025-53671
BaseFortify
Publication date: 2025-07-09
Last updated on: 2025-11-04
Assigner: Jenkins Project
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| jenkins | nouvola_divecloud | to 1.08 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-522 | The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. |
| CWE-256 | The product stores a password in plaintext within resources such as memory or files. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
The vulnerability in Jenkins Nouvola DiveCloud Plugin version 1.08 and earlier is that it does not mask DiveCloud API Keys and Credentials Encryption Keys when they are displayed on the job configuration form. This means that sensitive keys are visible and can potentially be observed or captured by unauthorized individuals.
How can this vulnerability impact me? :
This vulnerability can lead to unauthorized disclosure of sensitive API Keys and encryption credentials, which attackers could use to gain unauthorized access to systems or data, potentially compromising security and leading to further attacks.