CVE-2025-53667

MEDIUM

Jenkins Dead Man's Snitch Plugin 0.1 - Info Disclosure

Title source: llm

Description

Jenkins Dead Man's Snitch Plugin 0.1 does not mask Dead Man's Snitch tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

Scores

CVSS v3 5.3
EPSS 0.0004
EPSS Percentile 12.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Classification

CWE
CWE-522
Status published

Affected Products (2)

jenkins/dead_man\'s_snitch
org.jenkins-ci.plugins/deadmanssnitch Maven

Timeline

Published Jul 09, 2025
Tracked Since Feb 18, 2026