CVE-2024-47805 is a high-severity vulnerability affecting Jenkins Credentials Plugin versions 1380.va_435002fa_924 and earlier (excluding 1371.1373.v4eb_fa_b_7161e9). This flaw allows unredacted encrypted credential values of the SecretBytes type to be exposed when accessing item config.xml via the REST API or CLI. With a CVSS score of 7.5, this vulnerability presents a high risk of confidentiality compromise (C:H) due to its network-based attack vector (AV:N) and low attack complexity (AC:L), requiring no user interaction (UI:N) or privileges (PR:N). There is currently no evidence of active exploitation, public exploit code, or significant community discussion beyond a single mention and one media article.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1371.1373.v4eb_fa_b_7161e9CPE matchmatch criteria | cpe:2.3:a:jenkins:credentials:*:*:*:*:*:jenkins:*:* | ||
>= 1371.vfee6b_095f0a_3, < 1380.va_435002fa_924CPE matchmatch criteria | cpe:2.3:a:jenkins:credentials:*:*:*:*:*:jenkins:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.