PT-2025-44294 · Jenkins · Jenkins Byteguard Build Actions Plugin+1
CVE-2025-64145
·
Publicado
2025-10-29
·
Atualizado
2025-11-04
CVSS v3.1
4.3
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins ByteGuard Build Actions Plugin version 1.0
Description
The Jenkins ByteGuard Build Actions Plugin version 1.0 does not properly mask API tokens displayed on the job configuration form. This can allow attackers to observe and capture these tokens, potentially leading to unauthorized access or actions.
Recommendations
Update to a newer version of the Jenkins ByteGuard Build Actions Plugin that addresses this issue.
Correção
Missing Encryption of Sensitive Data
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Jenkins
Jenkins Byteguard Build Actions Plugin