CVE-2024-47805

Name
CVE-2024-47805
Description
Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentials using the `SecretBytes` type when accessing item `config.xml` via REST API or CLI.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
vendor-advisory https://www.jenkins.io/security/advisory/2024-10-02/#SECURITY-3373

Match rules

CPE URI Source package Min version Max version
jenkins-credentials-plugin == 1371.1373.v4eb_fa_b_7161e9 == 1371.1373.v4eb_fa_b_7161e9
jenkins-credentials-plugin >= 0 <= 1380.va_435002fa_924
cpe:2.3:a:jenkins:credentials:*:*:*:*:*:jenkins:*:* jenkins >= None < 1371.1373.v4eb_fa_b_7161e9
cpe:2.3:a:jenkins:credentials:*:*:*:*:*:jenkins:*:* jenkins >= 1371.vfee6b_095f0a_3 < 1380.va_435002fa_924

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
jenkins edge-community 2.479.1-r0 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
jenkins edge-community 2.479.1-r1 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
jenkins edge-community 2.516.1-r0 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
jenkins 3.22-community 2.479.1-r0 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
jenkins 3.22-community 2.479.1-r1 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable