Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-47805


Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentials using the `SecretBytes` type when accessing item `config.xml` via REST API or CLI.


Published

2024-10-02T16:15:10.753

Last Modified

2025-03-14T15:15:43.840

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    CWE-522
  • Type: Secondary
    CWE-522

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application jenkins credentials < 1371.1373.v4eb_fa_b_7161e9 Yes
Application jenkins credentials < 1380.va_435002fa_924 Yes

References