CVE-2024-47805: Jenkins Credentials

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentials using the `SecretBytes` type when accessing item `config.xml` via REST API or CLI.

Affected products

  • Jenkins Credentials: before 1371.1373.v4eb_fa_b_7161e9 (fixed in 1371.1373.v4eb_fa_b_7161e9); from 1371.vfee6b_095f0a_3, before 1380.va_435002fa_924 (fixed in 1380.va_435002fa_924)

Published 2024-10-02. Last modified 2026-06-17.