#VU113413 Cleartext storage of sensitive information in Statistics Gatherer - CVE-2025-53654
Published: July 29, 2025
Statistics Gatherer
Jenkins
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the affected application stores the AWS Secret Key unencrypted in its global configuration file "org.jenkins.plugins.statistics.gatherer.StatisticsConfiguration.xml" on the Jenkins controller as part of its configuration. A remote user can gain access to secret information.