Jenkins Zoho QEngine Plugin Displays Unmasked API Keys
Low severity
GitHub Reviewed
Published
Mar 19, 2025
to the GitHub Advisory Database
•
Updated Mar 21, 2025
Package
Affected versions
< 1.0.31.v4a
Patched versions
1.0.31.v4a_b_1db_6d6a_f2
Description
Published by the National Vulnerability Database
Mar 19, 2025
Published to the GitHub Advisory Database
Mar 19, 2025
Reviewed
Mar 20, 2025
Last updated
Mar 21, 2025
Jenkins Zoho QEngine Plugin 1.0.29.vfa_cc23396502 and earlier does not mask the QEngine API Key form field, increasing the potential for attackers to observe and capture it.
References