Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentials using the `SecretBytes` type when accessing item `config.xml` via REST API or CLI.
Metrics
Affected Vendors & Products
References
History
Wed, 13 Nov 2024 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Jenkins
Jenkins credentials |
|
Weaknesses | CWE-522 | |
CPEs | cpe:2.3:a:jenkins:credentials:*:*:*:*:*:jenkins:*:* | |
Vendors & Products |
Jenkins
Jenkins credentials |
|
Metrics |
cvssV3_1
|
Wed, 02 Oct 2024 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 02 Oct 2024 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentials using the `SecretBytes` type when accessing item `config.xml` via REST API or CLI. | |
References |
|
MITRE
Status: PUBLISHED
Assigner: jenkins
Published: 2024-10-02T15:35:03.653Z
Updated: 2024-10-02T16:30:38.170Z
Reserved: 2024-10-01T20:59:52.483Z
Link: CVE-2024-47805
Vulnrichment
Updated: 2024-10-02T16:30:33.317Z
NVD
Status : Analyzed
Published: 2024-10-02T16:15:10.753
Modified: 2024-11-13T17:32:51.983
Link: CVE-2024-47805
Redhat
No data.