Jenkins Sensedia Api Platform tools Plugin 1.0 stores the Sensedia API Manager integration token unencrypted in its global configuration file on the Jenkins controller, where it can be viewed by users with access to the Jenkins controller file system.
References
Link | Resource |
---|---|
https://www.jenkins.io/security/advisory/2025-07-09/#SECURITY-3551 | Vendor Advisory |
Configurations
History
01 Oct 2025, 20:27
Type | Values Removed | Values Added |
---|---|---|
First Time |
Jenkins sensedia Api Platform Tools
Jenkins |
|
CPE | cpe:2.3:a:jenkins:sensedia_api_platform_tools:1.0:*:*:*:*:jenkins:*:* | |
References | () https://www.jenkins.io/security/advisory/2025-07-09/#SECURITY-3551 - Vendor Advisory |
10 Jul 2025, 13:17
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
09 Jul 2025, 20:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-311 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
09 Jul 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-07-09 16:15
Updated : 2025-10-01 20:27
NVD link : CVE-2025-53673
Mitre link : CVE-2025-53673
CVE.ORG link : CVE-2025-53673
JSON object : View
Products Affected
jenkins
- sensedia_api_platform_tools
CWE
CWE-311
Missing Encryption of Sensitive Data