CVE-2025-30197

CVSS 3.1 Score 3.1 of 10 (low)

Details

Published Mar 19, 2025
Updated: Mar 21, 2025
CWE ID 549

Summary

CVE-2025-30197 is a vulnerability affecting the Jenkins Zoho QEngine Plugin version 1.0.29.vfa_cc23396502 and earlier. This issue allows attackers to potentially observe and capture the unmasked QEngine API Key form field during data transmission. The absence of masking functionality exposes this sensitive information, increasing the risk of unauthorized access to Zoho QEngine services. Organizations using the affected plugin version are recommended to apply the necessary updates or patches to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share