PT-2025-44293 · Jenkins · Jenkins Byteguard Build Actions Plugin+1

CVE-2025-64144

·

Publicado

2025-10-29

·

Atualizado

2025-11-04

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins ByteGuard Build Actions Plugin version 1.0
Description The Jenkins ByteGuard Build Actions Plugin version 1.0 stores API tokens unencrypted in config.xml files on the Jenkins controller. These files are accessible to users with Item/Extended Read permission, or those with access to the Jenkins controller file system. This allows unauthorized viewing of the API tokens.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Encryption of Sensitive Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-64144
GHSA-2VMR-8C82-X8XQ

Produtos afetados

Jenkins
Jenkins Byteguard Build Actions Plugin