CVE-2025-31727

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Apr 2, 2025
Updated: Apr 17, 2025
CWE ID 549

Summary

CVE-2025-31727 is a vulnerability affecting the AsakusaSatellite Plugin versions prior to 0.1.1 used in Jenkins. The issue lies in the unencrypted storage of AsakusaSatellite API keys within the job config.xml files on the Jenkins controller. This exposure puts these keys at risk for theft by users with Item/Extended Read permissions or those who gain access to the Jenkins controller file system. Unsecured API keys can lead to unauthorized access, compromising the integrity and confidentiality of Jenkins projects. It is strongly recommended that users update to the latest version of the plugin to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share