Jenkins Plugin Exposes API Tokens in Job Configuration
CVE-2025-64145

4.3MEDIUM

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
29 October 2025

What is CVE-2025-64145?

The ByteGuard Build Actions Plugin for Jenkins version 1.0 fails to adequately mask API tokens in the job configuration form. This oversight allows potential attackers to view and capture sensitive tokens, possibly leading to unauthorized access. It is crucial for users to be aware of this vulnerability and take steps to secure their Jenkins configurations, as exposed API tokens can significantly undermine application security.

Affected Version(s)

Jenkins ByteGuard Build Actions Plugin 0 <= 1.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.