CVE Vulnerabilities

CVE-2024-39460

Insertion of Sensitive Information into Log File

Published: Jun 26, 2024 | Modified: Oct 10, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
3.3 LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Ubuntu

Jenkins Bitbucket Branch Source Plugin 886.v44cf5e4ecec5 and earlier prints the Bitbucket OAuth access token as part of the Bitbucket URL in the build log in some cases.

Weakness

The product writes sensitive information to a log file.

Affected Software

Name Vendor Start Version End Version
Bitbucket_branch_source Jenkins * 886.v44cf5e4ecec5 (including)

Potential Mitigations

References