CVE-2025-53674
MEDIUM4.3EPSS 0.09%Jenkins Sensedia API Platform Plugin vulnerability exposes unencrypted tokens
發布日:2025/7/9修改日:2025/11/5
描述
Jenkins Sensedia Api Platform tools Plugin 1.0 does not mask the Sensedia API Manager integration token on the global configuration form, increasing the potential for attackers to observe and capture it.
受影響套件(1)
- Maven/org.jenkins-ci.plugins:sensedia-api-platformfrom 0, <= 1.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.3 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |