Token Exposure in Jenkins Job Configuration by CloudBees
CVE-2025-67638
4.3MEDIUM
What is CVE-2025-67638?
The Jenkins software up to version 2.540 and LTS version 2.528.2 has a vulnerability where build authorization tokens are not adequately masked in the job configuration form. This oversight allows potential attackers to view and capture sensitive tokens, posing a significant risk of unauthorized access and manipulation of build processes.
Affected Version(s)
Jenkins 2.541
Jenkins 2.541
Jenkins 2.528.3 < 2.528.*