Jenkins Curseforge Publisher Plugin 1.0 does not mask API Keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-hv42-crpx-q355 | Jenkins Curseforge Publisher Plugin does not mask API Keys displayed on the job configuration form |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 29 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-311 | |
| Metrics |
cvssV3_1
|
Wed, 29 Oct 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jenkins Curseforge Publisher Plugin 1.0 does not mask API Keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them. | |
| References |
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-10-29T14:12:18.241Z
Reserved: 2025-10-28T07:34:37.542Z
Link: CVE-2025-64147
Updated: 2025-10-29T14:11:59.961Z
Status : Received
Published: 2025-10-29T14:15:59.553
Modified: 2025-10-29T15:15:45.383
Link: CVE-2025-64147
No data.
OpenCVE Enrichment
No data.
Github GHSA