Количество 2
Количество 2
CVE-2024-47805
Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentials using the `SecretBytes` type when accessing item `config.xml` via REST API or CLI.
GHSA-62jv-j4w7-5hh8
Jenkins Credentials plugin reveals encrypted values of credentials to users with Extended Read permission
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2024-47805 Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentials using the `SecretBytes` type when accessing item `config.xml` via REST API or CLI. | CVSS3: 7.5 | 0% Низкий | больше 1 года назад | |
GHSA-62jv-j4w7-5hh8 Jenkins Credentials plugin reveals encrypted values of credentials to users with Extended Read permission | CVSS3: 4.3 | 0% Низкий | больше 1 года назад |
Уязвимостей на страницу