Jenkins Marketplace Plugin - Missing Password Field Masking

  • ZSB-25007
  • CVE-2025-0148
  • Low
  • 2.6
  • CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N

Missing password field masking in the Zoom Jenkins Marketplace plugin before version 1.6 may allow an unauthenticated user to conduct a disclosure of information via adjacent network access.

 

Users can update to the latest version at  https://plugins.jenkins.io/zoom/releases/.  

  • Zoom Jenkins Marketplace plugin before version 1.6

Reported by Jenkins CVE Numbering Authority.

Revision Date Description
1.0 02/03/2025

Initial publication.