Cleartext storage of sensitive information in User1st uTester - CVE-2025-53678
Published: July 31, 2025
User1st uTester
Detailed vulnerability description
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to the affected application stores the uTester JWT token unencrypted in its global configuration file io.jenkins.plugins.user1st.utester.UTesterPlugin.xml on the Jenkins controller as part of its configuration. A local user can gain access to secret information.