Token Exposure in Jenkins Job Configuration by CloudBees
CVE-2025-67638
4.3MEDIUM
What is CVE-2025-67638?
The Jenkins software up to version 2.540 and LTS version 2.528.2 has a vulnerability where build authorization tokens are not adequately masked in the job configuration form. This oversight allows potential attackers to view and capture sensitive tokens, posing a significant risk of unauthorized access and manipulation of build processes.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jenkins 2.541
Jenkins 2.541
Jenkins 2.528.3 < 2.528.*