Jenkins VAddy Plugin API Key Exposure Vulnerability
CVE-2025-53668
What is CVE-2025-53668?
The Jenkins VAddy Plugin (version 1.2.8 and earlier) poses a security risk by storing API authentication keys in an unencrypted format within the job config.xml files on the Jenkins controller. This lax security practice allows users with Item/Extended Read permissions, or who have access to the Jenkins controller's file system, to potentially view these sensitive keys, which could lead to unauthorized access and manipulation of linked services. It is crucial for users and administrators to assess their Jenkins installation and consider implementing measures to secure their jobs and associated configurations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jenkins VAddy Plugin 0 <= 1.2.8
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved