Unencrypted Credential Storage in Jenkins ReadyAPI Plugin by CloudBees
CVE-2025-53656
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 9 July 2025
What is CVE-2025-53656?
The Jenkins ReadyAPI Functional Testing Plugin prior to version 1.11 contains a security vulnerability that compromises sensitive information. It stores SLM License Access Keys, client secrets, and passwords in an unencrypted format in the job config.xml files on the Jenkins controller. This information can be accessed by users with the Item/Extended Read permission or those who have access to the Jenkins controller's file system, potentially exposing critical credentials to unauthorized users.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jenkins ReadyAPI Functional Testing Plugin 0 <= 1.11
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved