logo

CVE-2025-53743 org.jenkins-ci.plugins:applitools-eyes

Package

Manager: maven
Name: org.jenkins-ci.plugins:applitools-eyes
Vulnerable Version: >=0 <=1.16.5

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

EPSS: 0.0004 pctl0.11268

Details

Jenkins Applitools Eyes Plugin vulnerability does not mask API keys on its job configuration form Jenkins Applitools Eyes Plugin 1.16.5 and earlier does not mask Applitools API keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

Metadata

Created: 2025-07-09T18:30:47Z
Modified: 2025-07-09T22:38:56Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/07/GHSA-jmrv-rxgr-phvr/GHSA-jmrv-rxgr-phvr.json
CWE IDs: ["CWE-522"]
Alternative ID: GHSA-jmrv-rxgr-phvr
Finding: F035
Auto approve: 1