CVE-2025-31724
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Apr 2, 2025
Updated: Apr 17, 2025
CWE ID 256
Summary
CVE-2025-31724 is a vulnerability affecting the Jenkins Cadence vManager Plugin version 4.0.0-282.v5096a_c2db_275 and earlier. The issue lies in the unencrypted storage of Verisium Manager vAPI keys in job config.xml files on the Jenkins controller. Users with Extended Read permission or access to the Jenkins controller file system can view these sensitive keys, posing a potential security risk. It is strongly recommended that affected users update their plugins or implement additional access controls to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.