CVE-2025-53672 – Jenkins Kryptowire Plugin Unencrypted API Key Storage

The following table lists the changes that have been made to the
CVE-2025-53672 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Jul. 09, 2025

    Action Type Old Value New Value
    Added Description Jenkins Kryptowire Plugin 0.2 and earlier stores the Kryptowire API key unencrypted in its global configuration file on the Jenkins controller, where it can be viewed by users with access to the Jenkins controller file system.
    Added Reference https://www.jenkins.io/security/advisory/2025-07-09/#SECURITY-3525
Share the Post:

Related Posts