Information Exposure Affecting org.jenkins-ci.plugins:structs package, versions [,338.v848422169819)
Threat Intelligence
EPSS
0.04% (11th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JAVA-ORGJENKINSCIPLUGINS-7411174
- published 27 Jun 2024
- disclosed 27 Jun 2024
- credit Juan Pablo Santos, from Sanitas, SA
Introduced: 27 Jun 2024
CVE-2024-39458 Open this link in a new tabHow to fix?
Upgrade org.jenkins-ci.plugins:structs
to version 338.v848422169819 or higher.
Overview
Affected versions of this package are vulnerable to Information Exposure due to a failuire to configure a build step, it logs a warning message containing diagnostic information that may contain secrets passed as step parameters. Exploiting this vulnerability can result in accidental exposure of secrets through the default system log.