Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3100 | Jenkins exposes multi-line secrets through error messages |
Github GHSA |
GHSA-pj95-ph4q-4qm4 | Jenkins exposes multi-line secrets through error messages |
Wed, 13 Nov 2024 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins
Jenkins jenkins |
|
| CPEs | cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:* cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:* |
|
| Vendors & Products |
Jenkins
Jenkins jenkins |
|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Wed, 06 Nov 2024 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat
Redhat ocp Tools |
|
| CPEs | cpe:/a:redhat:ocp_tools:4.12::el8 cpe:/a:redhat:ocp_tools:4.13::el8 cpe:/a:redhat:ocp_tools:4.14::el8 cpe:/a:redhat:ocp_tools:4.15::el8 |
|
| Vendors & Products |
Redhat
Redhat ocp Tools |
Thu, 03 Oct 2024 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | jenkins: Exposure of multi-line secrets through error messages | |
| Weaknesses | CWE-209 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Wed, 02 Oct 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 02 Oct 2024 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jenkins 2.478 and earlier, LTS 2.462.2 and earlier does not redact multi-line secret values in error messages generated for form submissions involving the `secretTextarea` form field. | |
| References |
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-03-19T17:47:32.684Z
Reserved: 2024-10-01T20:59:52.483Z
Link: CVE-2024-47803
Updated: 2024-10-02T16:32:11.868Z
Status : Modified
Published: 2024-10-02T16:15:10.630
Modified: 2025-03-19T18:15:23.033
Link: CVE-2024-47803
OpenCVE Enrichment
No data.
EUVD
Github GHSA