CVE-2025-30197 Details
Description
Jenkins Zoho QEngine Plugin 1.0.29.vfa_cc23396502 and earlier does not mask the QEngine API Key form field, increasing the potential for attackers to observe and capture it.
A vulnerability exists in the Jenkins Zoho QEngine Plugin in versions through 1.0.29.vfa_cc23396502, where the QEngine API Key form field is not masked. This oversight increases the risk of unauthorized observation and capture of the API key, which is stored encrypted on disk but visible in job configuration files. Users of the plugin should update to version 1.0.31.v4a_b_1db_6d6a_f2, which addresses this issue by masking the API key in the form.
Users should update the Jenkins Zoho QEngine Plugin to version 1.0.31.v4a_b_1db_6d6a_f2, which includes the necessary fix.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.jenkins.io/security/advisory/2025-03-19/#SECURITY-3511 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-549 | Missing Password Field Masking | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| jenkins zoho qengine | <= 1.0.29.vfa_cc23396502 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 10, 2025 | Initial Analysis | [email protected] |
| Mar 21, 2025 | CVE Modified | CISA-ADP |
| Mar 19, 2025 | New CVE Received | [email protected] |