CVE-2025-53677

Jenkins Xooa Plugin 0.0.7 and earlier does not mask the Xooa Deployment Token on the global configuration form, increasing the potential for attackers to observe and capture it.
Configurations

No configuration.

History

10 Jul 2025, 13:17

Type Values Removed Values Added
Summary
  • (es) Jenkins Xooa Plugin 0.0.7 y versiones anteriores no enmascaran el token de implementación de Xooa en el formulario de configuración global, lo que aumenta la posibilidad de que los atacantes lo observen y lo capturen.

09 Jul 2025, 20:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CWE CWE-256

09 Jul 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-09 16:15

Updated : 2025-07-10 13:17


NVD link : CVE-2025-53677

Mitre link : CVE-2025-53677

CVE.ORG link : CVE-2025-53677


JSON object : View

Products Affected

No product.

CWE
CWE-256

Unprotected Storage of Credentials