CVE-2024-39460

Name
CVE-2024-39460
Description
Jenkins Bitbucket Branch Source Plugin 886.v44cf5e4ecec5 and earlier prints the Bitbucket OAuth access token as part of the Bitbucket URL in the build log in some cases.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
vendor-advisory https://www.jenkins.io/security/advisory/2024-06-26/#SECURITY-3363
http://www.openwall.com/lists/oss-security/2024/06/26/2

Match rules

CPE URI Source package Min version Max version
jenkins-bitbucket-branch-source-plugin >= 0 <= 886.v44cf5e4ecec5
cpe:2.3:a:jenkins:bitbucket_branch_source:*:*:*:*:*:jenkins:*:* jenkins >= None <= 886.v44cf5e4ecec5

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
jenkins edge-community 2.516.1-r0 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
jenkins edge-community 2.479.1-r1 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
jenkins edge-community 2.479.1-r0 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
jenkins 3.22-community 2.479.1-r1 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
jenkins 3.22-community 2.479.1-r0 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable