#VU113448 Cleartext storage of sensitive information in Kryptowire - CVE-2025-53672
Published: July 30, 2025
Kryptowire
Jenkins
Description
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to the affected application stores the Kryptowire API key unencrypted in its global configuration file "org.aerogear.kryptowire.GlobalConfigurationImpl.xml" on the Jenkins controller as part of its configuration. A local user can gain access to secret information.