Beveiligingsadvies

CVE-2025-27622

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-03-05 22:33:34
Laatst bijgewerkt 2025-03-06 16:19:56
Toegewezen door jenkins
CVSS-score 4.3
Status PUBLISHED

Beschrijving

Jenkins 2.499 and earlier, LTS 2.492.1 and earlier does not redact encrypted values of secrets when accessing `config.xml` of agents via REST API or CLI, allowing attackers with Agent/Extended Read permission to view encrypted values of secrets.