Jenkins Plugin Exposes API Tokens in Job Configuration
CVE-2025-64145
4.3MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 29 October 2025
What is CVE-2025-64145?
The ByteGuard Build Actions Plugin for Jenkins version 1.0 fails to adequately mask API tokens in the job configuration form. This oversight allows potential attackers to view and capture sensitive tokens, possibly leading to unauthorized access. It is crucial for users to be aware of this vulnerability and take steps to secure their Jenkins configurations, as exposed API tokens can significantly undermine application security.
Affected Version(s)
Jenkins ByteGuard Build Actions Plugin 0 <= 1.0