MEDIUMMaven

Jenkins does not encrypt secrets from POST config.xml submissions before storing them in job configurations

Jenkins does not encrypt secrets from POST config.xml submissions before storing them in job configurations

CVE-2026-53442Published 2 months agoUpdated 1 week agoSource: OSV

Affected packages

  • org.jenkins-ci.main:jenkins-corebefore 2.555.3

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
EPSS percentile

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.

Jenkins does not encrypt secrets from POST config.xml submissions before storing them in job configurations | HackTribune