CVE-2025-0148: Zoom Communications, Inc Zoom Jenkins Marketplace Plugin

Low severity, CVSS 2.6. EPSS: 0.2% chance of exploitation in the next 30 days.

Missing password field masking in the Zoom Jenkins Marketplace plugin before version 1.6 may allow an unauthenticated user to conduct a disclosure of information via adjacent network access.

Affected products

Published 2025-02-03. Last modified 2026-06-17.