Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-53656


Jenkins ReadyAPI Functional Testing Plugin 1.11 and earlier stores SLM License Access Keys, client secrets, and passwords unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.


Published

2025-07-09T16:15:25.037

Last Modified

2025-07-18T17:33:42.757

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-256

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application jenkins readyapi_functional_testing ≤ 1.11 Yes

References