CVE-2024-39460
Bitbucket OAuth access token exposed in the build log by Bitbucket Branch Source Plugin
4.3
MEDIUM
CVSS 3.1
EPSS 0.49%
描述
Bitbucket Branch Source Plugin 886.v44cf5e4ecec5 and earlier prints the Bitbucket OAuth access token as part of the Bitbucket URL in the build log in some cases. Bitbucket Branch Source Plugin 887.va_d359b_3d2d8d does not include the Bitbucket OAuth access token as part of the Bitbucket URL in the build log.
如何修補 CVE-2024-39460
要修補 CVE-2024-39460,請將受影響套件升級到下列已修補版本。
- —升級至 887.va 或更新版本
CVE-2024-39460 正在被利用嗎?
低 — EPSS 為 0.5%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 887.va
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.3 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |