CVE-2025-53666

MEDIUM4.3EPSS 0.16%

Jenkins Dead Man's Snitch Plugin vulnerability stores tokens in plain text

Published: 7/9/2025Modified: 11/5/2025
Also known as:GHSA-5pcv-7v3q-hw8j

Description

Jenkins Dead Man's Snitch Plugin 0.1 stores Dead Man's Snitch tokens unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

References (4)