API Key Exposure Vulnerability in Jenkins Zoho QEngine Plugin
CVE-2025-30197
3.1LOW
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 19 March 2025
What is CVE-2025-30197?
The Jenkins Zoho QEngine Plugin prior to version 1.0.29.vfa_cc23396502 fails to properly mask the QEngine API Key in the form fields. This oversight allows malicious actors to potentially observe and intercept the API Key, which could lead to unauthorized access and exploitation of services that rely on this key. To mitigate this risk, it is recommended that users upgrade to the latest version of the plugin and enforce best practices for API key management.
Affected Version(s)
Jenkins Zoho QEngine Plugin 0 <= 1.0.29.vfa_cc23396502