Jenkins Stack Hammer Plugin 1.0.6 and earlier stores Stack Hammer API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.
Metrics
Affected Vendors & Products
References
History
Thu, 17 Apr 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Jenkins
Jenkins stack Hammer |
|
CPEs | cpe:2.3:a:jenkins:stack_hammer:*:*:*:*:*:jenkins:*:* | |
Vendors & Products |
Jenkins
Jenkins stack Hammer |
Thu, 03 Apr 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-284 | |
Metrics |
cvssV3_1
|
Wed, 02 Apr 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Jenkins Stack Hammer Plugin 1.0.6 and earlier stores Stack Hammer API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system. | |
References |
|

Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-04-03T20:19:11.827Z
Reserved: 2025-04-01T12:50:10.765Z
Link: CVE-2025-31726

Updated: 2025-04-02T17:43:55.961Z

Status : Analyzed
Published: 2025-04-02T15:16:00.150
Modified: 2025-04-18T16:21:11.430
Link: CVE-2025-31726

No data.