Jenkins 2.478 and earlier, LTS 2.462.2 and earlier does not redact multi-line secret values in error messages generated for form submissions involving the secretTextarea
form field.
The product generates an error message that includes sensitive information about its environment, users, or associated data.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Jenkins | Jenkins | * | 2.462.3 (excluding) |
Jenkins | Jenkins | * | 2.479 (excluding) |
OCP-Tools-4.12-RHEL-8 | RedHat | jenkins-0:2.462.3.1730119132-3.el8 | * |
OCP-Tools-4.12-RHEL-8 | RedHat | jenkins-2-plugins-0:4.12.1730119231-1.el8 | * |
OCP-Tools-4.13-RHEL-8 | RedHat | jenkins-0:2.462.3.1729839924-3.el8 | * |
OCP-Tools-4.13-RHEL-8 | RedHat | jenkins-2-plugins-0:4.13.1729840148-1.el8 | * |
OCP-Tools-4.14-RHEL-8 | RedHat | jenkins-0:2.462.3.1729839727-3.el8 | * |
OCP-Tools-4.14-RHEL-8 | RedHat | jenkins-2-plugins-0:4.14.1729839844-1.el8 | * |
OCP-Tools-4.15-RHEL-8 | RedHat | jenkins-0:2.462.3.1729837947-3.el8 | * |
OCP-Tools-4.15-RHEL-8 | RedHat | jenkins-2-plugins-0:4.15.1729838165-1.el8 | * |