cbcvebase.
CVE-2019-10348
published 2019-07-11

CVE-2019-10348: Jenkins Gogs Plugin stored credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read…

high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
Jenkins Gogs Plugin stored credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.

Affected

9 ranges
VendorProductVersion rangeFixed in
jenkinscaliper_ci_plugin
jenkinsdependency_graph_viewer_plugin
jenkinsdocker_plugin
jenkinsembeddable_build_status_plugin
jenkinsgogs<= 1.0.14
jenkinsgogs_plugin
jenkinsids_to_allow_users_configuring_the_plugin
jenkinsport_allocator_plugin
jenkins_projectjenkins_gogs_plugin