Jenkins Nouvola DiveCloud Plugin 1.08 and earlier stores DiveCloud API Keys and Credentials Encryption Keys unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.
Metrics
Affected Vendors & Products
References
History
Fri, 18 Jul 2025 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Jenkins
Jenkins nouvola Divecloud |
|
CPEs | cpe:2.3:a:jenkins:nouvola_divecloud:*:*:*:*:*:jenkins:*:* | |
Vendors & Products |
Jenkins
Jenkins nouvola Divecloud |
Tue, 15 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Wed, 09 Jul 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-312 | |
Metrics |
cvssV3_1
|
Wed, 09 Jul 2025 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Jenkins Nouvola DiveCloud Plugin 1.08 and earlier stores DiveCloud API Keys and Credentials Encryption Keys unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system. | |
References |
|

Status: PUBLISHED
Assigner: jenkins
Published: 2025-07-09T15:39:38.401Z
Updated: 2025-07-09T19:13:42.645Z
Reserved: 2025-07-08T07:51:59.764Z
Link: CVE-2025-53670

Updated: 2025-07-09T18:48:23.694Z

Status : Analyzed
Published: 2025-07-09T16:15:26.490
Modified: 2025-07-18T18:48:33.803
Link: CVE-2025-53670

No data.