CVE Vulnerabilities

CVE-2024-47805

Insufficiently Protected Credentials

Published: Oct 02, 2024 | Modified: Mar 14, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentials using the SecretBytes type when accessing item config.xml via REST API or CLI.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

NameVendorStart VersionEnd Version
CredentialsJenkins*1371.1373.v4eb_fa_b_7161e9 (excluding)
CredentialsJenkins1371.vfee6b_095f0a_3 (including)1380.va_435002fa_924 (excluding)

Potential Mitigations

References