Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-hxjg-2jvf-h3rx | Jenkins's build authorization token is stored and displayed in plain text |
Wed, 17 Dec 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:* cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:* |
Thu, 11 Dec 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | org.jenkins-ci.main/jenkins-core: Jenkins authorization token leak | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 10 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins
Jenkins jenkins |
|
| Vendors & Products |
Jenkins
Jenkins jenkins |
Wed, 10 Dec 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-312 | |
| Metrics |
cvssV3_1
|
Wed, 10 Dec 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not mask build authorization tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them. | |
| References |
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-12-10T17:33:14.791Z
Reserved: 2025-12-09T17:33:01.215Z
Link: CVE-2025-67638
Updated: 2025-12-10T17:31:35.805Z
Status : Analyzed
Published: 2025-12-10T17:15:56.293
Modified: 2025-12-17T17:37:39.177
Link: CVE-2025-67638
OpenCVE Enrichment
Updated: 2025-12-10T21:33:10Z
Github GHSA