J
enkins ReadyAPI Functional Testing Plugin 1.11 and earlier stores SLM License Access Keys, client secrets, and passwords unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.
References
| Link | Resource |
|---|---|
| https://www.jenkins.io/security/advisory/2025-07-09/#SECURITY-3556 | Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2025/07/09/4 |
Configurations
History
04 Nov 2025, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
18 Jul 2025, 17:33
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.jenkins.io/security/advisory/2025-07-09/#SECURITY-3556 - Vendor Advisory | |
| CPE | cpe:2.3:a:jenkins:readyapi_functional_testing:*:*:*:*:*:jenkins:*:* | |
| First Time |
Jenkins
Jenkins readyapi Functional Testing |
10 Jul 2025, 13:17
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
09 Jul 2025, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-256 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
09 Jul 2025, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-07-09 16:15
Updated : 2025-11-04 22:16
NVD link : CVE-2025-53656
Mitre link : CVE-2025-53656
CVE.ORG link : CVE-2025-53656
JSON object : View
Products Affected
CWE
CWE-256
Plaintext Storage of a Password