API Key Exposure Vulnerability in Jenkins Zoho QEngine Plugin
CVE-2025-30197

3.1LOW

Key Information:

Vendor
Jenkins
Vendor
CVE Published:
19 March 2025

Summary

The Jenkins Zoho QEngine Plugin prior to version 1.0.29.vfa_cc23396502 fails to properly mask the QEngine API Key in the form fields. This oversight allows malicious actors to potentially observe and intercept the API Key, which could lead to unauthorized access and exploitation of services that rely on this key. To mitigate this risk, it is recommended that users upgrade to the latest version of the plugin and enforce best practices for API key management.

Affected Version(s)

Jenkins Zoho QEngine Plugin 0 <= 1.0.29.vfa_cc23396502

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.