CVE-2025-31728 - CERT CVE
ID CVE-2025-31728
Sažetak Jenkins AsakusaSatellite Plugin 0.1.1 and earlier does not mask AsakusaSatellite API keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.
Reference
CVSS
Base: 5.5
Impact: 3.4
Exploitability:2.1
Pristup
VektorSloženostAutentikacija
NETWORK LOW LOW
Impact
PovjerljivostCjelovitostDostupnost
LOW LOW LOW
CVSS vektor CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Zadnje važnije ažuriranje 17-04-2025 - 14:35
Objavljeno 02-04-2025 - 15:16