cbcvebase.
CVE-2024-47805
published 2024-10-02

CVE-2024-47805: Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentials using the…

PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.59%
44.3th percentile
Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentials using the `SecretBytes` type when accessing item `config.xml` via REST API or CLI.

Affected

9 ranges
VendorProductVersion rangeFixed in
jenkinscredentials< 1371.1373.v4eb_fa_b_7161e91371.1373.v4eb_fa_b_7161e9
jenkinscredentials>= 1371.vfee6b_095f0a_3 < 1380.va_435002fa_9241380.va_435002fa_924
jenkinscredentials_plugin
jenkinsjenkins_core
jenkinsjenkins_lts
jenkinsjenkins_weekly
jenkinsopenid_connect_authentication_plugin
jenkinsplain_credentials_plugin
jenkins_projectjenkins_credentials_plugin<= 1380.va_435002fa_924
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.