Jenkins 2.478 and earlier, LTS 2.462.2 and earlier does not redact multi-line secret values in error messages generated for form submissions involving the secretTextarea form field.
{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "2.462.3"
},
{
"fixed": "2.479"
}
],
"source": "CPE_FIELD",
"cpe": [
"cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*",
"cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:*"
]
}