CVE-2025-53661

Jenkins Testsigma Test Plan run Plugin 1.6 and earlier does not mask Testsigma API keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jenkins:testsigma_test_plan_run:*:*:*:*:*:jenkins:*:*

History

18 Jul 2025, 17:31

Type Values Removed Values Added
First Time Jenkins
Jenkins testsigma Test Plan Run
CPE cpe:2.3:a:jenkins:testsigma_test_plan_run:*:*:*:*:*:jenkins:*:*
References () https://www.jenkins.io/security/advisory/2025-07-09/#SECURITY-3515 - () https://www.jenkins.io/security/advisory/2025-07-09/#SECURITY-3515 - Vendor Advisory

10 Jul 2025, 13:17

Type Values Removed Values Added
Summary
  • (es) Jenkins Testsigma Test Plan run Plugin 1.6 y versiones anteriores no enmascara las claves API de Testsigma que se muestran en el formulario de configuración del trabajo, lo que aumenta la posibilidad de que los atacantes las observen y capturen.

09 Jul 2025, 20:15

Type Values Removed Values Added
CWE CWE-522
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3

09 Jul 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-09 16:15

Updated : 2025-07-18 17:31


NVD link : CVE-2025-53661

Mitre link : CVE-2025-53661

CVE.ORG link : CVE-2025-53661


JSON object : View

Products Affected

jenkins

  • testsigma_test_plan_run
CWE
CWE-522

Insufficiently Protected Credentials