CVE-2025-53655

Description

Jenkins Statistics Gatherer Plugin 2.0.3 and earlier does not mask the AWS Secret Key on the global configuration form, increasing the potential for attackers to observe and capture it.

Risk Information

Base Score
5.3
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
0.057

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2025-53654,CVE-2025-53655 are affected in Jenkins - statistics-gatherer 2.0.3Windows
Vulnerabilities CVE-2025-53654,CVE-2025-53655 are affected in Jenkins - statistics-gatherer for Linux 2.0.3Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234