Description
Jenkins Bitbucket Branch Source Plugin 886.v44cf5e4ecec5 and earlier prints the Bitbucket OAuth access token as part of the Bitbucket URL in the build log in some cases.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4Attack Vector: Network
Complexity: Low
Privileges: Low
User Interaction: None
Scope: Unchanged
Confidentiality: Low
Integrity: None
Availability: None
Affected Packages3 packages
🔴Vulnerability Details
3GHSABitbucket OAuth access token exposed in the build log by Bitbucket Branch Source Plugin↗2024-06-26 ▶ OSVBitbucket OAuth access token exposed in the build log by Bitbucket Branch Source Plugin↗2024-06-26 ▶ CVEListCVE-2024-39460: Jenkins Bitbucket Branch Source Plugin 886↗2024-06-26 ▶ 📋Vendor Advisories
2Red Hatjenkins: bitbucket: Improper neutralization of OAuth credentials↗2024-06-26 ▶ JenkinsJenkins Security Advisory 2024-06-26↗2024-06-26 ▶