Severity
5.5MEDIUM
EPSS
0.0%
top 98.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 31
Latest updateMay 24

Description

Jenkins Configuration as Code Plugin 1.20 and earlier did not treat the proxy password as a secret to be masked when logging or encrypted for export.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

🔴Vulnerability Details

3
GHSA
Plaintext Storage of a Password in Jenkins Configuration as Code Plugin2022-05-24
OSV
Plaintext Storage of a Password in Jenkins Configuration as Code Plugin2022-05-24
CVEList
CVE-2019-10345: Jenkins Configuration as Code Plugin 12019-07-31

📋Vendor Advisories

1
Jenkins
Jenkins Security Advisory 2019-07-312019-07-31