Jenkins Zoho QEngine Plugin 1.0.29.vfa_cc23396502 and earlier does not mask the QEngine API Key form field, increasing the potential for attackers to observe and capture it.
References
| Link | Resource |
|---|---|
| https://www.jenkins.io/security/advisory/2025-03-19/#SECURITY-3511 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2025-03-19 16:15
Updated : 2025-10-10 15:30
NVD link : CVE-2025-30197
Mitre link : CVE-2025-30197
CVE.ORG link : CVE-2025-30197
JSON object : View
Products Affected
jenkins
- zoho_qengine
CWE
CWE-549
Missing Password Field Masking
