Unrated severityNVD Advisory· Published Jul 4, 2025· Updated Dec 12, 2025
Jenkins-image: sensitive data disclosure when using openshift jenkins image
CVE-2024-9453
Description
A vulnerability was found in Red Hat OpenShift Jenkins. The bearer token is not obfuscated in the logs and potentially carries a high risk if those logs are centralized when collected. The token is typically valid for one year. This flaw allows a malicious user to jeopardize the environment if they have access to sensitive information.
Affected products
11- Red Hat/OpenShift Developer Tools and Servicesv5cpe:/a:redhat:ocp_tools
- osv-coords8 versionspkg:apk/chainguard/jenkins-2pkg:apk/chainguard/jenkins-2.462pkg:apk/chainguard/jenkins-2.492pkg:apk/chainguard/jenkins-2.504pkg:apk/chainguard/jenkins-2.516pkg:apk/chainguard/jenkins-2.528pkg:apk/wolfi/jenkins-2pkg:bitnami/jenkins
< 0+ 7 more
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)
- Jenkins/openshift-sync-pluginv5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- access.redhat.com/security/cve/CVE-2024-9453mitrevdb-entryx_refsource_REDHAT
- bugzilla.redhat.com/show_bug.cgimitreissue-trackingx_refsource_REDHAT
News mentions
0No linked articles in our index yet.