CVE 4.3 MEDIUM

CVE-2025-64147_CVE-2025-64147

4.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Description

Jenkins Curseforge Publisher Plugin 1.0 does not mask API Keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

Basic Information

ID CVE-2025-64147
Source jenkins
Published Oct 29, 2025 at 13:29
Modified Oct 29, 2025 at 14:12

Affected Product

Vendor Jenkins Project
Product Jenkins Curseforge Publisher Plugin
Affected Versions Jenkins Project Jenkins Curseforge Publisher Plugin 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.