Jenkins 2.478 and earlier, LTS 2.462.2 and earlier does not redact multi-line secret values in error messages generated for form submissions involving the `secretTextarea` form field.
2024-10-02T16:15:10.630
2025-03-19T18:15:23.033
Modified
CVSSv3.1: 4.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | jenkins | jenkins | < 2.462.3 | Yes |
Application | jenkins | jenkins | < 2.479 | Yes |