CVE-2024-47803

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Oct 2, 2024
Updated: Mar 19, 2025
CWE ID 209

Summary

CVE-2024-47803 is a vulnerability affecting Jenkins versions 2.478 and earlier, as well as LTS 2.462.2 and earlier. This issue permits the disclosure of multi-line secret values through error messages generated from form submissions involving the `secretTextarea` form field. These error messages do not redact the sensitive data properly, posing a risk of unauthorized access or data breaches. Users are urged to upgrade to a patched version of Jenkins to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share