cbcvebase.
CVE-2024-47805
published 2024-10-02

CVE-2024-47805: Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentials using the…

high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentials using the `SecretBytes` type when accessing item `config.xml` via REST API or CLI.

Affected

9 ranges
VendorProductVersion rangeFixed in
jenkinscredentials< 1371.1373.v4eb_fa_b_7161e91371.1373.v4eb_fa_b_7161e9
jenkinscredentials>= 1371.vfee6b_095f0a_3 < 1380.va_435002fa_9241380.va_435002fa_924
jenkinscredentials_plugin
jenkinsjenkins_core
jenkinsjenkins_lts
jenkinsjenkins_weekly
jenkinsopenid_connect_authentication_plugin
jenkinsplain_credentials_plugin
jenkins_projectjenkins_credentials_plugin<= 1380.va_435002fa_924