GHSA-xfx3-cr74-x3cv

Suggest an improvement
Source
https://github.com/advisories/GHSA-xfx3-cr74-x3cv
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/06/GHSA-xfx3-cr74-x3cv/GHSA-xfx3-cr74-x3cv.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-xfx3-cr74-x3cv
Aliases
  • CVE-2024-39458
Related
Published
2024-06-26T18:30:28Z
Modified
2024-11-06T14:54:14.378956Z
Severity
  • 3.1 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N CVSS Calculator
  • 2.3 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Exposure of secrets through system log in Jenkins Structs Plugin
Details

Structs Plugin provides utility functionality used, e.g., in Pipeline to instantiate and configure build steps, typically before their execution.

When Structs Plugin 337.v1b04ea4df7c8 and earlier fails to configure a build step, it logs a warning message containing diagnostic information that may contain secrets passed as step parameters.

This can result in accidental exposure of secrets through the default system log.

Structs Plugin 338.v848422169819 inspects the types of actual parameters before logging these warning messages, and limits detailed diagnostic information to FINE level log messages if secrets are involved. These log messages are not displayed in the default Jenkins system log.

Database specific
{
    "nvd_published_at": "2024-06-26T17:15:27Z",
    "cwe_ids": [
        "CWE-200",
        "CWE-209"
    ],
    "severity": "LOW",
    "github_reviewed": true,
    "github_reviewed_at": "2024-06-26T20:03:44Z"
}
References

Affected packages

Maven / org.jenkins-ci.plugins:structs

Package

Name
org.jenkins-ci.plugins:structs
View open source insights on deps.dev
Purl
pkg:maven/org.jenkins-ci.plugins/structs

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
338.v848422169819

Affected versions

1.*

1.1
1.1.1
1.2
1.3
1.4
1.5
1.6
1.7
1.8
1.9
1.10
1.12
1.13
1.14
1.15
1.16
1.17
1.18
1.19
1.20
1.21
1.22
1.23
1.24

308.*

308.v852b473a2b8c

317.*

317.vf68c51f71b_e2

318.*

318.va_f3ccb_729b_71

324.*

324.va_f5d6774f3a_d

325.*

325.vcb_307d2a_2782

337.*

337.v1b_04ea_4df7c8