Unencrypted Token Storage Vulnerability in Jenkins OpenShift Pipeline Plugin
CVE-2025-64143
4.3MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 29 October 2025
What is CVE-2025-64143?
The Jenkins OpenShift Pipeline Plugin version 1.0.57 and earlier exhibits a vulnerability where authorization tokens are stored unencrypted in the job config.xml files located on the Jenkins controller. This security flaw allows users with Item/Extended Read permissions, or those who have access to the Jenkins controller file system, to view sensitive tokens. This exposes a significant security risk as unauthorized access can lead to compromised credentials and further exploitation.
Affected Version(s)
Jenkins OpenShift Pipeline Plugin 0 <= 1.0.57