CVE-2025-67638
MEDIUMDescription
Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not mask build authorization tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| jenkins | jenkins |
| jenkins | jenkins |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-67638? +
How severe is CVE-2025-67638? +
What products are affected by CVE-2025-67638? +
How do I check if I'm vulnerable to CVE-2025-67638? +
Related Vulnerabilities
This vulnerability exists in CP Plus Wi-Fi Camera due to improper protection of sensitive information in runtime memory. An attacker …
The lack of encryption in the DuoxMe (formerly Blue) application binary in versions prior to 3.3.1 for iOS devices allows …
next-forge is a Next.js project boilerplate for modern web application. The BASEHUB_TOKEN commited in apps/web/.env.example. Users should avoid use of …
PMD is an extensible multilanguage static code analyzer. The passphrase for the PMD and PMD Designer release signing keys are …
This vulnerability exists in the Tinxy smart devices due to storage of credentials in plaintext within the device firmware. An …
Valmet DNA user passwords in plain text. This practice poses a security risk as attackers who gain access to local …