Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentials using the `SecretBytes` type when accessing item `config.xml` via REST API or CLI.
History

Wed, 13 Nov 2024 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins
Jenkins credentials
Weaknesses CWE-522
CPEs cpe:2.3:a:jenkins:credentials:*:*:*:*:*:jenkins:*:*
Vendors & Products Jenkins
Jenkins credentials
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Wed, 02 Oct 2024 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Oct 2024 15:45:00 +0000

Type Values Removed Values Added
Description Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentials using the `SecretBytes` type when accessing item `config.xml` via REST API or CLI.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published: 2024-10-02T15:35:03.653Z

Updated: 2024-10-02T16:30:38.170Z

Reserved: 2024-10-01T20:59:52.483Z

Link: CVE-2024-47805

cve-icon Vulnrichment

Updated: 2024-10-02T16:30:33.317Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-02T16:15:10.753

Modified: 2024-11-13T17:32:51.983

Link: CVE-2024-47805

cve-icon Redhat

No data.