CVE-2025-27623
CVE-2025-27623
Título es
CVE-2025-27623
Mié, 05/03/2025 – 23:15
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2025-27623
Descripción en
Jenkins 2.499 and earlier, LTS 2.492.1 and earlier does not redact encrypted values of secrets when accessing `config.xml` of views via REST API or CLI, allowing attackers with View/Read permission to view encrypted values of secrets.
06/03/2025
06/03/2025
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
Pendiente de análisis
Referencias
https://www.jenkins.io/security/advisory/2025-03-05/#SECURITY-3496
Enviar en el boletín
Off
