cbcvebase.
CVE-2024-39460
published 2024-06-26

CVE-2024-39460: Jenkins Bitbucket Branch Source Plugin 886.v44cf5e4ecec5 and earlier prints the Bitbucket OAuth access token as part of the Bitbucket URL in the build log in…

PriorityP420medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.49%
38.7th percentile
Jenkins Bitbucket Branch Source Plugin 886.v44cf5e4ecec5 and earlier prints the Bitbucket OAuth access token as part of the Bitbucket URL in the build log in some cases.

Affected

5 ranges
VendorProductVersion rangeFixed in
jenkinsbitbucket_branch_source<= 886.v44cf5e4ecec5
jenkinsbitbucket_branch_source_plugin
jenkinsstructs_plugin
jenkinswhen_structs_plugin
jenkins_projectjenkins_bitbucket_branch_source_plugin<= 886.v44cf5e4ecec5

CVSS provenance

nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.