CVE-2024-9453

A vulnerability was found in Red Hat OpenShift Jenkins. The bearer token is not obfuscated in the logs and potentially carries a high risk if those logs are centralized when collected. The token is typically valid for one year. This flaw allows a malicious user to jeopardize the environment if they have access to sensitive information.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:jenkins:jenkins:-:*:*:*:-:*:*:*
cpe:2.3:a:redhat:openshift_developer_tools_and_services:-:*:*:*:*:*:*:*

History

18 Aug 2025, 19:02

Type Values Removed Values Added
References () https://access.redhat.com/security/cve/CVE-2024-9453 - () https://access.redhat.com/security/cve/CVE-2024-9453 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2316231 - () https://bugzilla.redhat.com/show_bug.cgi?id=2316231 - Issue Tracking, Vendor Advisory
CPE cpe:2.3:a:jenkins:jenkins:-:*:*:*:-:*:*:*
cpe:2.3:a:redhat:openshift_developer_tools_and_services:-:*:*:*:*:*:*:*
First Time Jenkins
Redhat
Redhat openshift Developer Tools And Services
Jenkins jenkins

08 Jul 2025, 16:18

Type Values Removed Values Added
Summary
  • (es) Se encontró una vulnerabilidad en Red Hat OpenShift Jenkins. El token portador no está ofuscado en los registros y podría suponer un alto riesgo si estos registros se centralizan al momento de su recopilación. El token suele tener una validez de un año. Esta falla permite que un usuario malintencionado ponga en peligro el entorno si accede a información confidencial.

04 Jul 2025, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-04 09:15

Updated : 2025-08-18 19:02


NVD link : CVE-2024-9453

Mitre link : CVE-2024-9453

CVE.ORG link : CVE-2024-9453


JSON object : View

Products Affected

jenkins

  • jenkins

redhat

  • openshift_developer_tools_and_services
CWE
CWE-532

Insertion of Sensitive Information into Log File