CVE-2019-10343

Severity
3.3LOW
EPSS
0.0%
top 97.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 31
Latest updateMay 24

Description

Jenkins Configuration as Code Plugin 1.24 and earlier did not properly apply masking to values expected to be hidden when logging the configuration being applied.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 1.8 | Impact: 1.4

Affected Packages3 packages

🔴Vulnerability Details

3
OSV
Insertion of Sensitive Information into Log File in Jenkins Configuration as Code Plugin2022-05-24
GHSA
Insertion of Sensitive Information into Log File in Jenkins Configuration as Code Plugin2022-05-24
CVEList
CVE-2019-10343: Jenkins Configuration as Code Plugin 12019-07-31

📋Vendor Advisories

1
Jenkins
Jenkins Security Advisory 2019-07-312019-07-31
CVE-2019-10343 (LOW CVSS 3.3) | Jenkins Configuration as Code Plugi | cvebase.io