Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentials using the SecretBytes
type when accessing item config.xml
via REST API or CLI.
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Credentials | Jenkins | * | 1371.1373.v4eb_fa_b_7161e9 (excluding) |
Credentials | Jenkins | 1371.vfee6b_095f0a_3 (including) | 1380.va_435002fa_924 (excluding) |