VYPR

Maven package

org.jenkins-ci.plugins/applitools-eyes

pkg:maven/org.jenkins-ci.plugins/applitools-eyes

Vulnerabilities (3)

  • CVE-2025-53743MedJul 9, 2025
    affected <= 1.16.5

    Jenkins Applitools Eyes Plugin 1.16.5 and earlier does not mask Applitools API keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

  • CVE-2025-53742MedJul 9, 2025
    affected <= 1.16.5

    Jenkins Applitools Eyes Plugin 1.16.5 and earlier stores Applitools API keys unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.

  • CVE-2025-53658MedJul 9, 2025
    affected < 1.16.6fixed 1.16.6

    Jenkins Applitools Eyes Plugin 1.16.5 and earlier does not escape the Applitools URL on the build page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.