CVE-2025-53655: Jenkins Statistics Gatherer
Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.
Jenkins Statistics Gatherer Plugin 2.0.3 and earlier does not mask the AWS Secret Key on the global configuration form, increasing the potential for attackers to observe and capture it.
Affected products
- Jenkins Statistics Gatherer: up to and including 2.0.3
Published 2025-07-09. Last modified 2026-06-17.