Jenkins Stack Hammer Plugin 1.0.6 and earlier stores Stack Hammer API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.
Metrics
Affected Vendors & Products
References
History
Thu, 17 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins
Jenkins stack Hammer |
|
| CPEs | cpe:2.3:a:jenkins:stack_hammer:*:*:*:*:*:jenkins:*:* | |
| Vendors & Products |
Jenkins
Jenkins stack Hammer |
Thu, 03 Apr 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
cvssV3_1
|
Wed, 02 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jenkins Stack Hammer Plugin 1.0.6 and earlier stores Stack Hammer API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system. | |
| References |
|
Status: PUBLISHED
Assigner: jenkins
Published: 2025-04-02T14:59:53.108Z
Updated: 2025-04-03T20:19:11.827Z
Reserved: 2025-04-01T12:50:10.765Z
Link: CVE-2025-31726
Updated: 2025-04-02T17:43:55.961Z
Status : Analyzed
Published: 2025-04-02T15:16:00.150
Modified: 2025-04-18T16:21:11.430
Link: CVE-2025-31726
No data.