A vulnerability was found in Red Hat OpenShift Jenkins. The bearer token is not obfuscated in the logs and potentially carries a high risk if those logs are centralized when collected. The token is typically valid for one year. This flaw allows a malicious user to jeopardize the environment if they have access to sensitive information.
{
"cna_assigner": "redhat",
"cwe_ids": [
"CWE-532"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/9xxx/CVE-2024-9453.json"
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "1.1.0.818.v3883b_3b_df89a_"
}
],
"source": "AFFECTED_FIELD"
}