cbcvebase.
CVE-2019-10343
published 2019-08-07

CVE-2019-10343: Due to an incomplete fix of CVE-2019-10343, Jenkins Configuration as Code Plugin 1.26 and earlier did not properly apply masking to some values expected to be…

PriorityP410low3.3CVSS 3.1
AVLACLPRLUINSUCLINAN
EPSS
0.37%
28.9th percentile
Due to an incomplete fix of CVE-2019-10343, Jenkins Configuration as Code Plugin 1.26 and earlier did not properly apply masking to some values expected to be hidden when logging the configuration being applied.

Affected

14 ranges
VendorProductVersion rangeFixed in
jenkinsamazon_ec2_plugin
jenkinsbetween_configuration_as_code_plugin
jenkinsconfiguration_as_code<= 1.26
jenkinsconfiguration_as_code<= 1.24
jenkinsconfiguration_as_code_plugin
jenkinsdeprecated_groovy_libraries_plugin
jenkinsgoogle_kubernetes_engine_plugin
jenkinsmaven_integration_plugin
jenkinsmaven_release_plug-in_plugin
jenkinssandbox_protection_in_script_security_plugin
jenkinsscript_security_plugin
jenkinssince_configuration_as_code_plugin
jenkinsskytap_cloud_ci_plugin
jenkins_projectjenkins_configuration_as_code_plugin

CVSS provenance

nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.