cbcvebase.
CVE-2019-10348
published 2019-07-11

CVE-2019-10348: Jenkins Gogs Plugin stored credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read…

PriorityP346high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.67%
74.1th percentile
Jenkins Gogs Plugin stored credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.

Affected

9 ranges
VendorProductVersion rangeFixed in
jenkinscaliper_ci_plugin
jenkinsdependency_graph_viewer_plugin
jenkinsdocker_plugin
jenkinsembeddable_build_status_plugin
jenkinsgogs<= 1.0.14
jenkinsgogs_plugin
jenkinsids_to_allow_users_configuring_the_plugin
jenkinsport_allocator_plugin
jenkins_projectjenkins_gogs_plugin

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.