cbcvebase.
CVE-2019-10283
published 2019-04-04

CVE-2019-10283: Jenkins mabl Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read…

PriorityP346high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.77%
75.7th percentile
Jenkins mabl Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.

Affected

46 ranges· showing 25
VendorProductVersion rangeFixed in
jenkinsamazon_sns_build_notifier_plugin
jenkinsaqua_security_scanner_plugin
jenkinsassembla_auth_plugin
jenkinsaudit_to_database_plugin
jenkinsaws_cloudwatch_logs_publisher_plugin
jenkinsaws_elastic_beanstalk_publisher_plugin
jenkinsbitbucket_approve_plugin
jenkinsbugzilla_plugin
jenkinscloudcoreo_deploytime_plugin
jenkinscloudformation_plugin
jenkinscloudshare_docker-machine_plugin
jenkinscrowd_integration_plugin
jenkinsdeployhub_plugin
jenkinsdiawi_upload_plugin
jenkinsftp_publisher_plugin
jenkinsgearman_plugin
jenkinshockeyapp_plugin
jenkinshyper.sh_commons_plugin
jenkinsirc_plugin
jenkinsjabber_server_plugin
jenkinsjira_issue_updater_plugin
jenkinsklaros-testmanagement_plugin
jenkinskoji_plugin
jenkinsminio_storage_plugin
jenkinsnetsparker_enterprise_scan_plugin

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.