CVE-2025-53743 – org.jenkins-ci.plugins:applitools-eyes
Package
Manager: maven
Name: org.jenkins-ci.plugins:applitools-eyes
Vulnerable Version: >=0 <=1.16.5
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS: 0.0004 pctl0.11268
Details
Jenkins Applitools Eyes Plugin vulnerability does not mask API keys on its job configuration form Jenkins Applitools Eyes Plugin 1.16.5 and earlier does not mask Applitools API keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.
Metadata
Created: 2025-07-09T18:30:47Z
Modified: 2025-07-09T22:38:56Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/07/GHSA-jmrv-rxgr-phvr/GHSA-jmrv-rxgr-phvr.json
CWE IDs: ["CWE-522"]
Alternative ID: GHSA-jmrv-rxgr-phvr
Finding: F035
Auto approve: 1