Cyber Resilience

CVE-2025-53674

Jenkins Sensedia Api Platform Tools 1.0

Published
09 July 2025
Modified
17 June 2026
Patch / advisory
CVSS Score v3.1 5.3
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score 0.0025 17th percentile
Risk Priority 35 floored blend · peak EPSS

Summary

CVE-2025-53674 is a medium-severity Plaintext Storage of a Password (CWE-256) vulnerability in Jenkins Sensedia Api Platform Tools. Its CVSS base score is 5.3 (Medium).

Operationally, ranked at the 17th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified map to IA-5 (Authenticator Management) and SC-28 (Protection of Information at Rest) — see the control section below for these in your framework.

OWASP Top 10 for Web (2025)

EU & UK References

Vulnerability Data

Jenkins Sensedia Api Platform tools Plugin 1.0 does not mask the Sensedia API Manager integration token on the global configuration form, increasing the potential for attackers to observe and capture it.

CWE(s)

Related Threats

CVEs Like This One

CVE-2025-53673Same product: Jenkins Sensedia Api Platform Tools
CVE-2025-53662Same vendor: Jenkins
CVE-2025-53664Same vendor: Jenkins
CVE-2025-53655Same vendor: Jenkins
CVE-2025-53656Same vendor: Jenkins
CVE-2026-57302Same vendor: Jenkins
CVE-2025-31724Same vendor: Jenkins
CVE-2025-53675Same vendor: Jenkins
CVE-2025-53665Same vendor: Jenkins
CVE-2025-53677Same vendor: Jenkins

Affected Assets

jenkins
sensedia api platform tools
1.0

Mitigating Controls

Control response

Prevent
Stop it (NIST 800-53)
  • IA-5 Authenticator Management
  • SC-28 Protection of Information at Rest
  • PE-19 Information Leakage
Detect
Catch it (NIST detect / respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)

Mitigating Controls (NIST 800-53 r5) AI

prevent

Requires protection of authenticators (such as API tokens) against unauthorized disclosure, directly addressing the unmasked token on the configuration form.

prevent

Mandates cryptographic or equivalent protection of sensitive information (the integration token) at rest, preventing exposure via the Jenkins global configuration page.

prevent

Limits information leakage from organizational systems, mitigating the risk of the token being observed or captured through the plugin's configuration interface.

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

PR.DS-01 mostly match
prevents

Encryption and hashing of data-at-rest directly prevent plaintext password storage in files.

PR.AA-01 partial match
prevents

Credential management practices normally include secure storage requirements for passwords.

PR.DS-10 partial match
prevents

Protecting data-in-use can limit exposure of passwords held in memory.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

degrades

Directly requires secure handling and protection of authentication information, preventing plaintext password storage.

prevents

Requires use of cryptography to protect sensitive data such as passwords at rest.

prevents

Secure coding practices would prevent developers from writing code that stores passwords in plaintext.

degrades

Mandates secure authentication mechanisms that inherently require hashed or encrypted credentials rather than plaintext.

none

Requires secure deletion of sensitive information, indirectly reducing exposure of stored plaintext passwords.

References