VYPR

Maven package

org.jenkins-ci.plugins/vaddy-plugin

pkg:maven/org.jenkins-ci.plugins/vaddy-plugin

Vulnerabilities (2)

  • CVE-2025-53669MedJul 9, 2025
    affected <= 1.2.8

    Jenkins VAddy Plugin 1.2.8 and earlier does not mask Vaddy API Auth Keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

  • CVE-2025-53668MedJul 9, 2025
    affected <= 1.2.8

    Jenkins VAddy Plugin 1.2.8 and earlier stores Vaddy API Auth Keys unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.