Description
Jenkins 2.478 and earlier, LTS 2.462.2 and earlier does not redact multi-line secret values in error messages generated for form submissions involving the `secretTextarea` form field.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2010-0903 Vulnerability (CVE-2010-0903)
WordPress Plugin Better Font Awesome Cross-Site Scripting (2.0.3)
TYPO3 Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2005-4875)
MySQL CVE-2013-3807 Vulnerability (CVE-2013-3807)
WordPress Plugin Limit Login Attempts Cross-Site Scripting (1.7.1)