Sensitive Data Exposure in Jenkins Credentials Plugin by Jenkins
CVE-2024-47805
7.5HIGH
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 2 October 2024
What is CVE-2024-47805?
The Jenkins Credentials Plugin exposes sensitive data as it fails to properly redact encrypted credential values when accessing the item configuration file, config.xml
, through the REST API or Command-Line Interface (CLI). This vulnerability compromises the integrity of credential management, allowing unauthorized access to sensitive information if the appropriate security measures are not implemented. Specific versions of the plugin are impacted, necessitating prompt action to mitigate the risks.
Affected Version(s)
Jenkins Credentials Plugin 0 <= 1380.va_435002fa_924
Jenkins Credentials Plugin 1371.1373.v4eb_fa_b_7161e9