Unencrypted Authentication Token Exposure in Jenkins IBM Cloud DevOps Plugin
CVE-2025-53663
6.5MEDIUM
What is CVE-2025-53663?
The Jenkins IBM Cloud DevOps Plugin versions 2.0.16 and earlier store SonarQube authentication tokens in an unencrypted format within the job config.xml files on the Jenkins controller. This vulnerability allows users with Item/Extended Read permission or access to the Jenkins controller file system to potentially view these sensitive tokens, compromising the security and integrity of the system.
Affected Version(s)
Jenkins IBM Cloud DevOps Plugin 0 <= 2.0.16