Vulnerabilities (CVE)

Filtered by vendor Jenkins Subscribe
Filtered by product Xooa
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-53676 1 Jenkins 1 Xooa 2025-10-03 N/A 6.5 MEDIUM
Jenkins Xooa Plugin 0.0.7 and earlier stores the Xooa Deployment Token unencrypted in its global configuration file on the Jenkins controller, where it can be viewed by users with access to the Jenkins controller file system.
CVE-2025-53677 1 Jenkins 1 Xooa 2025-10-03 N/A 5.3 MEDIUM
Jenkins Xooa Plugin 0.0.7 and earlier does not mask the Xooa Deployment Token on the global configuration form, increasing the potential for attackers to observe and capture it.