CVE-2024-39458

LOW

Jenkins Structs < 337.v1b_04ea_4df7c8 - Error Information Exposure

Title source: rule
STIX 2.1

Description

When Jenkins Structs Plugin 337.v1b_04ea_4df7c8 and earlier fails to configure a build step, it logs a warning message containing diagnostic information that may contain secrets passed as step parameters, potentially resulting in accidental exposure of secrets through the default system log.

Scores

CVSS v3 3.1
EPSS 0.0021
EPSS Percentile 42.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-209
Status published
Products (2)
jenkins/structs < 337.v1b_04ea_4df7c8
org.jenkins-ci.plugins/structs 0 - 338.v848422169819Maven
Published Jun 26, 2024
Tracked Since Feb 18, 2026