VYPR

Maven package

com.ibm.devops/ibm-cloud-devops

pkg:maven/com.ibm.devops/ibm-cloud-devops

Vulnerabilities (1)

  • CVE-2025-53663MedJul 9, 2025
    affected <= 2.0.16

    Jenkins IBM Cloud DevOps Plugin 2.0.16 and earlier stores SonarQube authentication tokens unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.