Boletines de Vulnerabilidades

CVE-2025-64146

   
Software afectado JENKINS
 
Jenkins Curseforge Publisher Plugin 1.0 stores API Keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission, or access to the Jenkins controller file system.

Link:

https://nvd.nist.gov/vuln/detail/CVE-2025-64146