Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentials using the `SecretBytes` type when accessing item `config.xml` via REST API or CLI.
2024-10-02T16:15:10.753
2025-03-14T15:15:43.840
Modified
CVSSv3.1: 7.5 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | jenkins | credentials | < 1371.1373.v4eb_fa_b_7161e9 | Yes |
Application | jenkins | credentials | < 1380.va_435002fa_924 | Yes |