Information Disclosure Vulnerability in Zoom Jenkins Marketplace Plugin
CVE-2025-0142

4.3MEDIUM

Key Information:

Vendor
Zoom Communications, Inc
Status
Zoom Jenkins Marketplace Plugin
Vendor
CVE Published:
30 January 2025

Summary

The Zoom Jenkins Marketplace plugin prior to version 1.4 is susceptible to an information disclosure vulnerability. This flaw arises from the cleartext storage of sensitive information, which could potentially be exploited by an authenticated user to gain unauthorized access to sensitive data through network interactions. Organizations utilizing this plugin must take immediate steps to upgrade to the latest version to mitigate risks associated with this vulnerability.

Affected Version(s)

Zoom Jenkins Marketplace plugin 0 < 1.4

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.