Medium severity4.3NVD Advisory· Published Jun 26, 2024· Updated Jun 17, 2026
CVE-2024-39460
CVE-2024-39460
Description
Jenkins Bitbucket Branch Source Plugin 886.v44cf5e4ecec5 and earlier prints the Bitbucket OAuth access token as part of the Bitbucket URL in the build log in some cases.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins:cloudbees-bitbucket-branch-sourceMaven | < 887.va | 887.va |
Affected products
3- cpe:2.3:a:jenkins:bitbucket_branch_source:*:*:*:*:*:jenkins:*:*Range: <=886.v44cf5e4ecec5
- Range: 0
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-x8mf-jcmf-r79fghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-39460ghsaADVISORY
- www.jenkins.io/security/advisory/2024-06-26/nvdVendor AdvisoryWEB
- www.openwall.com/lists/oss-security/2024/06/26/2nvdMailing ListWEB
- github.com/jenkinsci/bitbucket-branch-source-plugin/commit/ad359b3d2d8d6c114025d81abc59b3c9acb636dfghsaWEB
News mentions
1- Jenkins Security Advisory 2024-06-26Jenkins Security Advisories · Jun 26, 2024