Feed/CVE-2026-53442
CVE-2026-53442MEDIUMCVSS 5.3

CVE-2026-53442

Published Jun 10, 2026·Updated Aug 13, 2026

NVD Description

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not encrypt secrets from POST config.xml submissions before storing them in job configurations unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission, or access to the Jenkins controller file system.

Affected Packages (1)

org.jenkins-ci.main:jenkins-coreMAVEN
Fixed in 2.555.3

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free