Jenkins IFTTT Build Notifier Plugin 1.2 and earlier stores IFTTT Maker Channel Keys unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.
Metrics
Affected Vendors & Products
References
History
Fri, 18 Jul 2025 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Jenkins
Jenkins ifttt Build Notifier |
|
CPEs | cpe:2.3:a:jenkins:ifttt_build_notifier:*:*:*:*:*:jenkins:*:* | |
Vendors & Products |
Jenkins
Jenkins ifttt Build Notifier |
Tue, 15 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Wed, 09 Jul 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-256 | |
Metrics |
cvssV3_1
|
Wed, 09 Jul 2025 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Jenkins IFTTT Build Notifier Plugin 1.2 and earlier stores IFTTT Maker Channel Keys unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system. | |
References |
|

Status: PUBLISHED
Assigner: jenkins
Published: 2025-07-09T15:39:33.696Z
Updated: 2025-07-09T19:14:37.396Z
Reserved: 2025-07-08T07:51:59.763Z
Link: CVE-2025-53662

Updated: 2025-07-09T18:49:26.592Z

Status : Analyzed
Published: 2025-07-09T16:15:25.640
Modified: 2025-07-18T17:31:15.557
Link: CVE-2025-53662

No data.