CVE-2025-64147
Description
Jenkins Curseforge Publisher Plugin 1.0 does not mask API Keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Jenkins Curseforge Publisher Plugin 1.0 does not mask API Keys on the job configuration form, exposing them to attackers with view access.
Vulnerability
Description
The Jenkins Curseforge Publisher Plugin version 1.0 fails to mask API Keys displayed on the job configuration form [1][3]. This means that the API Key field is shown in plain text rather than being obfuscated (e.g., with asterisks), which is a standard security practice for sensitive credentials in Jenkins forms.
Exploitation
An attacker who has at least Job/Configure permission (or any permission that allows viewing the job configuration page) can directly observe the API Key in plain text [1][2]. No special network position or additional authentication bypass is required; the vulnerability is present in the user interface itself.
Impact
Successful exploitation allows an attacker to capture the plaintext API Key. With this key, the attacker could potentially authenticate to the Curseforge service as the plugin's configured user, leading to unauthorized actions such as publishing or modifying project artifacts on Curseforge [1][3].
Mitigation
As of the advisory date (2025-10-29), no fixed version of the Curseforge Publisher Plugin has been released [1][2]. The plugin is listed among those with unresolved security issues. Users should consider removing or disabling the plugin if it is not essential, or restrict access to job configuration pages to trusted administrators only.
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins:curseforge-publisherMaven | <= 1.0 | — |
Affected products
2- Range: = 1.0
- Jenkins Project/Jenkins Curseforge Publisher Pluginv5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/advisories/GHSA-hv42-crpx-q355ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-64147ghsaADVISORY
- www.jenkins.io/security/advisory/2025-10-29/ghsavendor-advisoryWEB
- www.openwall.com/lists/oss-security/2025/10/29/2ghsaWEB
News mentions
1- Jenkins Security Advisory 2025-10-29Jenkins Security Advisories · Oct 29, 2025