CVE Vulnerabilities

CVE-2024-47805

Insufficiently Protected Credentials

Published: Oct 02, 2024 | Modified: Nov 13, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentials using the SecretBytes type when accessing item config.xml via REST API or CLI.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

Name Vendor Start Version End Version
Credentials Jenkins * 1371.1373.v4eb_fa_b_7161e9 (excluding)
Credentials Jenkins 1371.vfee6b_095f0a_3 (including) 1380.va_435002fa_924 (excluding)

Potential Mitigations

References