Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-6782 | Jenkins Zoho QEngine Plugin 1.0.29.vfa_cc23396502 and earlier does not mask the QEngine API Key form field, increasing the potential for attackers to observe and capture it. |
Github GHSA |
GHSA-2x3g-rr4w-4qrp | Jenkins Zoho QEngine Plugin Displays Unmasked API Keys |
Fri, 10 Oct 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins
Jenkins zoho Qengine |
|
| CPEs | cpe:2.3:a:jenkins:zoho_qengine:*:*:*:*:*:jenkins:*:* | |
| Vendors & Products |
Jenkins
Jenkins zoho Qengine |
Fri, 21 Mar 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-549 | |
| Metrics |
cvssV3_1
|
Wed, 19 Mar 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jenkins Zoho QEngine Plugin 1.0.29.vfa_cc23396502 and earlier does not mask the QEngine API Key form field, increasing the potential for attackers to observe and capture it. | |
| References |
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-03-21T14:08:19.969Z
Reserved: 2025-03-18T14:36:31.051Z
Link: CVE-2025-30197
Updated: 2025-03-21T14:05:41.847Z
Status : Analyzed
Published: 2025-03-19T16:15:34.060
Modified: 2025-10-10T15:30:05.280
Link: CVE-2025-30197
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA