Jenkins Curseforge Publisher Plugin, Information Disclosure, CVE-2025-XXXX (Moderate)

Listen to this Post

The CVE in the Jenkins Curseforge Publisher Plugin stems from improper handling of sensitive data within the job configuration. The plugin is designed to interact with CurseForge’s API, requiring users to input their API key for authentication. Normally, Jenkins masks such sensitive strings to prevent accidental exposure. However, this plugin fails to implement that masking. When a job is configured, the API key is stored in plaintext within the job’s `config.xml` file on the Jenkins controller’s disk. Furthermore, the plugin’s configuration form, which is accessible to users with Item/Extended Read permission, displays the API key in a clear-text field instead of a password field that would obscure the characters. This allows any user with the necessary permissions to view the Jenkins web interface or gain file system access to directly read and exfiltrate the unencrypted API keys, compromising the associated CurseForge account.
Platform: Jenkins Plugin
Version: <= 1.0
Vulnerability : Information Disclosure
Severity: Moderate
date: 2024-10-29

Prediction: 2024-11-26

What Undercode Say:

`grep -r “apiKey” $JENKINS_HOME/jobs//config.xml`

`curl -H “X-API-Token: ” https://api.curseforge.com/v1/games`

How Exploit:

Access job configuration page via web UI. Read plaintext API key from form. Alternatively, read the `config.xml` file from the controller file system. Use the stolen key for unauthorized CurseForge API calls.

Protection from this CVE

Upgrade plugin when patch is available. Restrict Item/Extended Read permissions. Manually audit `config.xml` files and rotate exposed API keys.

Impact:

Unauthorized CurseForge account access. Potential for malicious project uploads or modifications.

🎯Let’s Practice Exploiting & Learn Patching For Free:

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top