{"id":"CVE-2024-47805","aliases":["GHSA-62jv-j4w7-5hh8"],"url":"https://o3.security/vulnerability/CVE-2024-47805","summary":"Jenkins Credentials plugin reveals encrypted values of credentials to users with Extended Read permission","details":"Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentials using the `SecretBytes` type (e.g., Certificate credentials, or Secret file credentials from Plain Credentials Plugin) when accessing item `config.xml` via REST API or CLI.\n\nThis allows attackers with Item/Extended Read permission to view encrypted `SecretBytes` values in credentials.\n\nThis issue is similar to SECURITY-266 in the 2016-05-11 security advisory, which applied to the `Secret` type used for inline secrets and some credentials types.\n\nCredentials Plugin 1381.v2c3a_12074da_b_ redacts the encrypted values of credentials using the `SecretBytes` type in item `config.xml` files.\n\nThis fix is only effective on Jenkins 2.479 and newer, LTS 2.462.3 and newer. While Credentials Plugin 1381.v2c3a_12074da_b_ can be installed on Jenkins 2.463 through 2.478 (both inclusive), encrypted values of credentials using the `SecretBytes` type will not be redacted when accessing item `config.xml` via REST API or CLI. ","published":"2024-10-02T16:15:10.753Z","modified":"2026-07-09T16:45:00.662418Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.jenkins-ci.plugins:credentials","fixedVersion":"1381.v2c3a"},{"ecosystem":"Maven","name":"org.jenkins-ci.plugins:credentials","fixedVersion":"1371.1373.v4eb"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://www.jenkins.io/security/advisory/2024-10-02/#SECURITY-3373"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-47805"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T16:45:00.662418Z"}}