Jenkins Support Core Plugin 2.79 and earlier does not redact some sensitive information in the support bundle.
The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.
Link | Tags |
---|---|
https://www.jenkins.io/security/advisory/2022-02-15/#SECURITY-2186 | issue tracking patch vendor advisory |