CVE-2025-0142Cleartext Storage of Sensitive Info in Communications INC Zoom Jenkins Marketplace Plugin

Severity
4.3MEDIUMNVD
EPSS
0.1%
top 76.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 30

Description

Cleartext storage of sensitive information in the Zoom Jenkins Marketplace plugin before version 1.4 may allow an authenticated user to conduct a disclosure of information via network access.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

🔴Vulnerability Details

2
GHSA
Jenkins Zoom Plugin Stores Sensitive Information in Cleartext2025-01-30
OSV
Jenkins Zoom Plugin Stores Sensitive Information in Cleartext2025-01-30

📋Vendor Advisories

1
Jenkins
Jenkins Security Advisory 2025-01-222025-01-22