CVE-2024-47805
published 2024-10-02CVE-2024-47805: Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentials using the…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.59%
44.3th percentile
Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentials using the `SecretBytes` type when accessing item `config.xml` via REST API or CLI.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | credentials | < 1371.1373.v4eb_fa_b_7161e9 | 1371.1373.v4eb_fa_b_7161e9 |
| jenkins | credentials | >= 1371.vfee6b_095f0a_3 < 1380.va_435002fa_924 | 1380.va_435002fa_924 |
| jenkins | credentials_plugin | — | — |
| jenkins | jenkins_core | — | — |
| jenkins | jenkins_lts | — | — |
| jenkins | jenkins_weekly | — | — |
| jenkins | openid_connect_authentication_plugin | — | — |
| jenkins | plain_credentials_plugin | — | — |
| jenkins_project | jenkins_credentials_plugin | <= 1380.va_435002fa_924 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Jenkins Credentials plugin reveals encrypted values of credentials to users with Extended Read permission
ghsa·2024-10-02
CVE-2024-47805 [MEDIUM] CWE-200 Jenkins Credentials plugin reveals encrypted values of credentials to users with Extended Read permission
Jenkins Credentials plugin reveals encrypted values of credentials to users with Extended Read permission
Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentials using the `SecretBytes` type (e.g., Certificate credentials, or Secret file credentials from Plain Credentials Plugin) when accessing item `config.xml` via REST API or CLI.
This allows attackers with Item/Extended Read permission to view encrypted `SecretBytes` values in credentials.
This issue is similar to SECURITY-266 in the 2016-05-11 security advisory, which applied to the `Secret` type used for inline secrets and some credentials types.
Credentials Plugin 1381.v2c3a_12074da_b_ redacts the encrypted values of credentials using the `Sec
OSV
Jenkins Credentials plugin reveals encrypted values of credentials to users with Extended Read permission
osv·2024-10-02
CVE-2024-47805 [MEDIUM] Jenkins Credentials plugin reveals encrypted values of credentials to users with Extended Read permission
Jenkins Credentials plugin reveals encrypted values of credentials to users with Extended Read permission
Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentials using the `SecretBytes` type (e.g., Certificate credentials, or Secret file credentials from Plain Credentials Plugin) when accessing item `config.xml` via REST API or CLI.
This allows attackers with Item/Extended Read permission to view encrypted `SecretBytes` values in credentials.
This issue is similar to SECURITY-266 in the 2016-05-11 security advisory, which applied to the `Secret` type used for inline secrets and some credentials types.
Credentials Plugin 1381.v2c3a_12074da_b_ redacts the encrypted values of credentials using the `Sec
Jenkins
Jenkins Security Advisory 2024-10-02
vendor_jenkins·2024-10-02·CVSS 4.3
CVE-2024-47803 [MEDIUM] Jenkins Security Advisory 2024-10-02
Title: Jenkins Security Advisory 2024-10-02
Jenkins Security Advisory 2024-10-02
Jenkins Security Home
For Administrators
Overview
Terminology
Vulnerabilities and Scoring
Security Advisories
Security Issues
Advisory Schedule
Vulnerabilities in Plugins
How We Fix Security Issues
For Reporters
Reporting Vulnerabilities
Jenkins CNA
For Maintainers
Overview
Vulnerabilities in Plugins
Jenkins Security Team
About
Contributions
This advisory announces vulnerabilities in the following Jenkins deliverables:
Jenkins (core)
Credentials
Plugin
OpenId Connect Authentication
Plugin
Descriptions
Exposure of multi-line secrets through error messages in Jenkins
SECURITY-3451
/
CVE-2024-47803
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-10-02
Published