← Back

CVE-2025-67638

nvd nist
Published: Dec 10, 2025Modified: Jun 17, 2026

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not mask build authorization tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

Affected (2)

Products: Jenkins: Jenkins
1 product
Jenkins
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Jenkins
Before 2.541
Before 2.528.3

References (1)

Source: jenkinsci-cert@googlegroups.com
Vendor Advisory

Timeline

No history available yet.