CVE-2025-53667
MEDIUM4.3EPSS 0.10%Jenkins Dead Man's Snitch Plugin vulnerability does not mask tokens
Published: 7/9/2025Modified: 11/5/2025
Also known as:GHSA-m248-72rh-cpx4
Description
Jenkins Dead Man's Snitch Plugin 0.1 does not mask Dead Man's Snitch tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.
Affected packages (1)
- Maven/org.jenkins-ci.plugins:deadmanssnitchfrom 0, <= 0.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.3 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |