CVE-2024-39460

Severity
4.3MEDIUM
EPSS
0.2%
top 56.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 26

Description

Jenkins Bitbucket Branch Source Plugin 886.v44cf5e4ecec5 and earlier prints the Bitbucket OAuth access token as part of the Bitbucket URL in the build log in some cases.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages3 packages

🔴Vulnerability Details

3
GHSA
Bitbucket OAuth access token exposed in the build log by Bitbucket Branch Source Plugin2024-06-26
OSV
Bitbucket OAuth access token exposed in the build log by Bitbucket Branch Source Plugin2024-06-26
CVEList
CVE-2024-39460: Jenkins Bitbucket Branch Source Plugin 8862024-06-26

📋Vendor Advisories

2
Red Hat
jenkins: bitbucket: Improper neutralization of OAuth credentials2024-06-26
Jenkins
Jenkins Security Advisory 2024-06-262024-06-26