Bitbucket OAuth access token exposed in the build log by Bitbucket Branch Source Plugin
Moderate severity
GitHub Reviewed
Published
Jun 26, 2024
to the GitHub Advisory Database
•
Updated Jun 26, 2024
Package
Affected versions
<= 886.v44cf5e4ecec5
Patched versions
887.va
Description
Published by the National Vulnerability Database
Jun 26, 2024
Published to the GitHub Advisory Database
Jun 26, 2024
Reviewed
Jun 26, 2024
Last updated
Jun 26, 2024
Bitbucket Branch Source Plugin 886.v44cf5e4ecec5 and earlier prints the Bitbucket OAuth access token as part of the Bitbucket URL in the build log in some cases.
Bitbucket Branch Source Plugin 887.va_d359b_3d2d8d does not include the Bitbucket OAuth access token as part of the Bitbucket URL in the build log.
References