CVE-2025-53650

Jenkins Credentials Binding Plugin 687.v619cb_15e923f and earlier does not properly mask (i.e., replace with asterisks) credentials present in exception error messages that are written to the build log.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jenkins:credentials_binding:*:*:*:*:*:jenkins:*:*

History

18 Jul 2025, 18:00

Type Values Removed Values Added
CWE CWE-522
CPE cpe:2.3:a:jenkins:credentials_binding:*:*:*:*:*:jenkins:*:*
References () https://www.jenkins.io/security/advisory/2025-07-09/#SECURITY-3499 - () https://www.jenkins.io/security/advisory/2025-07-09/#SECURITY-3499 - Vendor Advisory
First Time Jenkins credentials Binding
Jenkins

10 Jul 2025, 13:17

Type Values Removed Values Added
Summary
  • (es) Jenkins Credentials Binding Plugin 687.v619cb_15e923f y anteriores no enmascaran correctamente (es decir, no reemplazan con asteriscos) las credenciales presentes en los mensajes de error de excepción que se escriben en el registro de compilación.

09 Jul 2025, 21:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.3

09 Jul 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-09 16:15

Updated : 2025-07-18 18:00


NVD link : CVE-2025-53650

Mitre link : CVE-2025-53650

CVE.ORG link : CVE-2025-53650


JSON object : View

Products Affected

jenkins

  • credentials_binding
CWE
CWE-522

Insufficiently Protected Credentials