Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not mask build authorization tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.
Metrics
Affected Vendors & Products
References
History
Thu, 11 Dec 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | org.jenkins-ci.main/jenkins-core: Jenkins authorization token leak | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 10 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins
Jenkins jenkins |
|
| Vendors & Products |
Jenkins
Jenkins jenkins |
Wed, 10 Dec 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-312 | |
| Metrics |
cvssV3_1
|
Wed, 10 Dec 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not mask build authorization tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them. | |
| References |
|
Status: PUBLISHED
Assigner: jenkins
Published: 2025-12-10T16:50:37.570Z
Updated: 2025-12-10T17:33:14.791Z
Reserved: 2025-12-09T17:33:01.215Z
Link: CVE-2025-67638
Updated: 2025-12-10T17:31:35.805Z
Status : Received
Published: 2025-12-10T17:15:56.293
Modified: 2025-12-10T18:16:22.887
Link: CVE-2025-67638