CVE-2025-31724

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Apr 2, 2025
Updated: Apr 17, 2025
CWE ID 256

Summary

CVE-2025-31724 is a vulnerability affecting the Jenkins Cadence vManager Plugin version 4.0.0-282.v5096a_c2db_275 and earlier. The issue lies in the unencrypted storage of Verisium Manager vAPI keys in job config.xml files on the Jenkins controller. Users with Extended Read permission or access to the Jenkins controller file system can view these sensitive keys, posing a potential security risk. It is strongly recommended that affected users update their plugins or implement additional access controls to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share