{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-53657","assignerOrgId":"39769cd5-e6e2-4dc8-927e-97b3aa056f5b","state":"PUBLISHED","assignerShortName":"jenkins","dateReserved":"2025-07-08T07:51:59.762Z","datePublished":"2025-07-09T15:39:30.813Z","dateUpdated":"2025-11-04T21:12:04.123Z"},"containers":{"cna":{"providerMetadata":{"orgId":"39769cd5-e6e2-4dc8-927e-97b3aa056f5b","shortName":"jenkins","dateUpdated":"2025-07-09T15:39:30.813Z"},"affected":[{"vendor":"Jenkins Project","product":"Jenkins ReadyAPI Functional Testing Plugin","versions":[{"version":"0","versionType":"maven","lessThanOrEqual":"1.11","status":"affected"}],"defaultStatus":"unknown"}],"descriptions":[{"lang":"en","value":"Jenkins ReadyAPI Functional Testing Plugin 1.11 and earlier does not mask SLM License Access Keys, client secrets, and passwords displayed on the job configuration form, increasing the potential for attackers to observe and capture them."}],"references":[{"name":"Jenkins Security Advisory 2025-07-09","url":"https://www.jenkins.io/security/advisory/2025-07-09/#SECURITY-3556","tags":["vendor-advisory"]}]},"adp":[{"problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-522","lang":"en","description":"CWE-522 Insufficiently Protected Credentials"}]}],"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":4.3,"attackVector":"NETWORK","baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","integrityImpact":"NONE","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"NONE","privilegesRequired":"LOW","confidentialityImpact":"LOW"}},{"other":{"type":"ssvc","content":{"timestamp":"2025-07-09T18:50:12.031409Z","id":"CVE-2025-53657","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-07-09T19:15:11.504Z"}},{"title":"CVE Program Container","references":[{"url":"http://www.openwall.com/lists/oss-security/2025/07/09/4"}],"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2025-11-04T21:12:04.123Z"}}]}}