Jenkins Marketplace Plugin - Missing Password Field Masking
- ZSB-25007
- CVE-2025-0148
- Low
- 2.6
- CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
Missing password field masking in the Zoom Jenkins Marketplace plugin before version 1.6 may allow an unauthenticated user to conduct a disclosure of information via adjacent network access.
Users can update to the latest version at https://plugins.jenkins.io/zoom/releases/.
- Zoom Jenkins Marketplace plugin before version 1.6
Reported by Jenkins CVE Numbering Authority.
Revision | Date | Description |
---|---|---|
1.0 | 02/03/2025 | Initial publication. |