Jenkins Sensedia Api Platform tools Plugin 1.0 does not mask the Sensedia API Manager integration token on the global configuration form, increasing the potential for attackers to observe and capture it.
Metrics
Affected Vendors & Products
References
History
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 09 Jul 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-256 | |
| Metrics |
cvssV3_1
|
Wed, 09 Jul 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jenkins Sensedia Api Platform tools Plugin 1.0 does not mask the Sensedia API Manager integration token on the global configuration form, increasing the potential for attackers to observe and capture it. | |
| References |
|
Status: PUBLISHED
Assigner: jenkins
Published: 2025-07-09T15:39:40.807Z
Updated: 2025-07-09T19:13:17.415Z
Reserved: 2025-07-08T07:51:59.764Z
Link: CVE-2025-53674
Updated: 2025-07-09T18:47:00.452Z
Status : Awaiting Analysis
Published: 2025-07-09T16:15:26.927
Modified: 2025-07-10T13:17:30.017
Link: CVE-2025-53674
No data.