CVE-2024-47803: Medium severity jenkins lts vulnerability
Jenkins
Jenkins provides the secretTextarea form field for multi-line secrets.
Jenkins 2.478 and earlier, LTS 2.462.2 and earlier does not redact multi-line secret values in error messages generated for form submissions involving the secretTextarea form field.
This can result in exposure of multi-line secrets through those error messages, e.g., in the system log.
Jenkins 2.479, LTS 2.462.3 redacts multi-line secret values in error messages generated for form submissions involving the secretTextarea form field.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-47803?
CVE-2024-47803 is considered a high severity vulnerability due to the potential exposure of sensitive multi-line secrets.
How do I fix CVE-2024-47803?
To fix CVE-2024-47803, upgrade Jenkins to version 2.479 or LTS version 2.462.3 or later.
What versions are affected by CVE-2024-47803?
Jenkins versions 2.478 and earlier, as well as LTS version 2.462.2 and earlier, are affected by CVE-2024-47803.
What is the impact of CVE-2024-47803?
The impact of CVE-2024-47803 is the potential exposure of sensitive information in error messages related to the secretTextarea field.
Is there a workaround for CVE-2024-47803?
There is no officially recommended workaround for CVE-2024-47803, so upgrading is the best course of action.