Low severity3.1NVD Advisory· Published Mar 19, 2025· Updated Jun 17, 2026
CVE-2025-30197
CVE-2025-30197
Description
Jenkins Zoho QEngine Plugin 1.0.29.vfa_cc23396502 and earlier does not mask the QEngine API Key form field, increasing the potential for attackers to observe and capture it.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
io.jenkins.plugins:zohoqengineMaven | < 1.0.31.v4a_b_1db_6d6a_f2 | 1.0.31.v4a_b_1db_6d6a_f2 |
Affected products
3- cpe:2.3:a:jenkins:zoho_qengine:*:*:*:*:*:jenkins:*:*Range: <=1.0.29.vfa_cc23396502
- Range: 0
Patches
Vulnerability mechanics
References
4News mentions
1- Jenkins Security Advisory 2025-03-19Jenkins Security Advisories · Mar 19, 2025