Cyber Resilience

CVE-2025-53671

Exposed Creds in Jenkins Nouvola Divecloud ≤ 1.08

Published
09 July 2025
Modified
17 June 2026
Patch / advisory
CVSS Score v3.1 6.5
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score 0.0018 8th percentile
Risk Priority 35 floored blend · peak EPSS

Summary

CVE-2025-53671 is a medium-severity Plaintext Storage of a Password (CWE-256) vulnerability in Jenkins Nouvola Divecloud. Its CVSS base score is 6.5 (Medium).

Operationally, ranked at the 8th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified map to IA-5 (Authenticator Management) and SI-15 (Information Output Filtering) — see the control section below for these in your framework.

OWASP Top 10 for Web (2025)

EU & UK References

Vulnerability Data

Jenkins Nouvola DiveCloud Plugin 1.08 and earlier does not mask DiveCloud API Keys and Credentials Encryption Keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

CWE(s)

Related Threats

CVEs Like This One

CVE-2025-53670Same product: Jenkins Nouvola Divecloud
CVE-2023-2633Same vendor: Jenkins
CVE-2025-53669Same vendor: Jenkins
CVE-2023-2632Same vendor: Jenkins
CVE-2025-53660Same vendor: Jenkins
CVE-2025-53674Same vendor: Jenkins
CVE-2025-53662Same vendor: Jenkins
CVE-2023-32988Same vendor: Jenkins
CVE-2025-53667Same vendor: Jenkins
CVE-2024-47805Same vendor: Jenkins

Affected Assets

jenkins
nouvola divecloud
≤ 1.08

Mitigating Controls

Control response

Prevent
Stop it (NIST 800-53)
  • IA-5 Authenticator Management
  • SI-15 Information Output Filtering
  • SC-28 Protection of Information at Rest
Detect
Catch it (NIST detect / respond)

Harden
Shrink the surface (DISA STIG)
  • 1 hardening rule · 1 OS baseline
Validate
Prove the fix (OWASP ASVS)
  • V11.3.3

Mitigating Controls (NIST 800-53 r5) AI

prevent

Requires secure generation, storage, and display of authenticators so that API keys and encryption keys are never rendered in plaintext on configuration forms.

prevent

Mandates output filtering that blocks sensitive credential values from being emitted to job configuration pages or any user interface.

prevent

Requires cryptographic protection of sensitive information at rest, directly addressing the plaintext storage and exposure of DiveCloud keys described by CWE-256/522.

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

PR.DS-01 full match
prevents

Encrypting data-at-rest fully prevents insecure credential storage while only partially satisfying the broader data-protection outcome.

PR.DS-02 full match
prevents

Encrypting data-in-transit fully prevents interception of credentials in motion while only partially satisfying the broader data-protection outcome.

PR.AA-01 mostly match
prevents

Credential management practices directly reduce insecure storage/transmission but do not guarantee encryption or transport protection.

PR.AA-04 mostly match
prevents

Protecting identity assertions covers conveyance of credentials but is narrower than full credential lifecycle protection.

PR.AA-03 partial match
prevents

Authentication policies can enforce stronger credential handling yet address only verification, not storage or transit protection.

PR.DS-10 partial match
prevents

Protecting data-in-use can limit exposure of passwords held in memory.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

degrades

Directly requires secure handling and protection of authentication information, preventing plaintext password storage.

prevents

Requires use of cryptography to protect sensitive data such as passwords at rest.

prevents

Forbidding clear-text transmission and display of passwords, plus the use of stronger alternatives to passwords, prevents credentials from being obtained or reused by attackers.

prevents

Acceptable-use expectations that cover protection of credentials and information assets throughout their lifecycle discourage practices that expose or mishandle authentication material.

prevents

Contractual clauses that survive termination help ensure that credentials and other secrets are not retained or misused after employment ends.

prevents

Regular reminders about password security and personal accountability make users less likely to store or transmit credentials in cleartext or other unprotected forms.

References