VYPR

Maven package

org.jenkins-ci.plugins/curseforge-publisher

pkg:maven/org.jenkins-ci.plugins/curseforge-publisher

Vulnerabilities (2)

  • CVE-2025-64147Oct 29, 2025
    affected <= 1.0

    Jenkins Curseforge Publisher Plugin 1.0 does not mask API Keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

  • CVE-2025-64146Oct 29, 2025
    affected <= 1.0

    Jenkins Curseforge Publisher Plugin 1.0 stores API Keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission, or access to the Jenkins controller file system.