Vulnerability GHSA-8qr4-27mh-hqfr

Medium Risk
MEDIUM RISK
CVSS Score: 4.3
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
3 months ago
June 24, 2026 at 03:31 PM UTC
Jenkins Job Configuration History Plugin doesn't redact encrypted values of secrets in job and agent configurations
1.10.0 - 2.6.0 and 2.8.0 - 2.17.0 and 2.19.0 - 2.30.0
1.10.0 - 2.6.0 and 2.8.0 - 2.17.0 and 2.19.0 - 2.30.0

Summary

Jenkins Job Configuration History Plugin doesn't redact encrypted values of secrets in job and agent configurations

Details

Jenkins Job Configuration History Plugin 1356.ve360da_6c523a_ and earlier does not redact the encrypted values of secrets when displaying historical job and agent configurations through its "View as XML" / "(RAW)" feature and its configuration diff views.

This allows attackers with Item/Extended Read permission (but not Item/Configure permission) to view the encrypted values of secrets, such as build trigger tokens, that Jenkins would otherwise redact from the configuration shown to them.

Job Configuration History Plugin 1367.vc8fa_b_15101dc redacts the encrypted values of secrets when displaying historical job and agent configurations through its "View as XML" / "(RAW)" feature and its configuration diff views to users lacking Item/Configure permission.

Timeline

Published
3 months ago
June 24, 2026 at 03:31 PM UTC
Last Modified
2 days ago
September 25, 2026 at 06:15 PM UTC