CVE-2026-57287: Medium severity Jenkins Job Configuration History Plugin vulnerability
Jenkins Job Configuration History Plugin 1356.ve360da6c523a and earlier does not redact the encrypted values of secrets when displaying historical job and agent configurations, allowing attackers with Extended Read permission to view encrypted secret values that would otherwise be redacted.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Jenkins Job Configuration History Pluginto a version that resolves this vulnerability.Fixed in 1356.ve360da_6c523a_Patch Jenkins Job Configuration History Plugin 1356.ve360da_6c523a_ - Compensating control
Reduce users with Extended Read permission to only those who require it, since attackers with Extended Read permission could view encrypted secret values that are not redacted in historical job and agent configurations.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57287?
CVE-2026-57287 has a risk rating of 37, indicating significant severity.
How do I fix CVE-2026-57287?
To fix CVE-2026-57287, update the Jenkins Job Configuration History Plugin to version 1357 or later.
What does CVE-2026-57287 affect?
CVE-2026-57287 affects the Jenkins Job Configuration History Plugin version 1356.ve360da_6c523a_ and earlier.
Who is at risk from CVE-2026-57287?
Attackers with Extended Read permission are at risk of exploiting CVE-2026-57287 to view sensitive encrypted secret values.
What are the consequences of CVE-2026-57287?
CVE-2026-57287 can lead to the exposure of sensitive information, as encrypted secret values are visible in historical configurations.