CVE-2019-10367
published 2019-08-07CVE-2019-10367: Due to an incomplete fix of CVE-2019-10343, Jenkins Configuration as Code Plugin 1.26 and earlier did not properly apply masking to some values expected to be…
PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.38%
30.3th percentile
Due to an incomplete fix of CVE-2019-10343, Jenkins Configuration as Code Plugin 1.26 and earlier did not properly apply masking to some values expected to be hidden when logging the configuration being applied.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | avatar_plugin | — | — |
| jenkins | build_pipeline_plugin | — | — |
| jenkins | codefresh_integration_plugin | — | — |
| jenkins | configuration_as_code | <= 1.26 | — |
| jenkins | configuration_as_code_plugin | — | — |
| jenkins | file_system_scm_plugin | — | — |
| jenkins | gitlab_authentication_plugin | — | — |
| jenkins | google_cloud_messaging_notification_plugin | — | — |
| jenkins | jclouds_plugin | — | — |
| jenkins | jenkins_instance_with_this_plugin | — | — |
| jenkins | mask_passwords_plugin | — | — |
| jenkins | pegdown_formatter_plugin | — | — |
| jenkins | relution_enterprise_appstore_publisher_plugin | — | — |
| jenkins | simple_travis_pipeline_runner_plugin | — | — |
| jenkins | testlink_plugin | — | — |
| jenkins | vmware_lab_manager_slaves_plugin | — | — |
| jenkins | wall_display_master_project_plugin | — | — |
| jenkins | xl_testview_plugin | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Insertion of Sensitive Information into Log File in Jenkins Configuration as Code Plugin
ghsa·2022-05-24
CVE-2019-10367 [MEDIUM] CWE-532 Insertion of Sensitive Information into Log File in Jenkins Configuration as Code Plugin
Insertion of Sensitive Information into Log File in Jenkins Configuration as Code Plugin
Configuration as Code Plugin logs the changes it applies to the Jenkins system log. Secrets such as passwords should be masked (i.e. replaced with asterisks) in that log to prevent accidental disclosure. Configuration as Code Plugin inspects the type and looks for a field, getter, or constructor argument corresponding to the property, making the secret detection much more robust for the purpose of log message masking. This was implemented in the [fix for SECURITY-1279 in the 2019-07-31 security advisory](https://www.jenkins.io/security/advisory/2019-07-31/#SECURITY-1279).
That fix was incomplete and did not cover a log message written to the logger `io.jenkins.plugins.casc.impl.configurators.DataBoun
OSV
Insertion of Sensitive Information into Log File in Jenkins Configuration as Code Plugin
osv·2022-05-24
CVE-2019-10367 [MEDIUM] Insertion of Sensitive Information into Log File in Jenkins Configuration as Code Plugin
Insertion of Sensitive Information into Log File in Jenkins Configuration as Code Plugin
Configuration as Code Plugin logs the changes it applies to the Jenkins system log. Secrets such as passwords should be masked (i.e. replaced with asterisks) in that log to prevent accidental disclosure. Configuration as Code Plugin inspects the type and looks for a field, getter, or constructor argument corresponding to the property, making the secret detection much more robust for the purpose of log message masking. This was implemented in the [fix for SECURITY-1279 in the 2019-07-31 security advisory](https://www.jenkins.io/security/advisory/2019-07-31/#SECURITY-1279).
That fix was incomplete and did not cover a log message written to the logger `io.jenkins.plugins.casc.impl.configurators.DataBoun
Jenkins
Jenkins Security Advisory 2019-08-07
vendor_jenkins·2019-08-07·CVSS 5.5
CVE-2019-10367 [MEDIUM] Jenkins Security Advisory 2019-08-07
Title: Jenkins Security Advisory 2019-08-07
Jenkins Security Advisory 2019-08-07
Jenkins Security Home
For Administrators
Overview
Terminology
Vulnerabilities and Scoring
Security Advisories
Security Issues
Advisory Schedule
Vulnerabilities in Plugins
How We Fix Security Issues
For Reporters
Reporting Vulnerabilities
Jenkins CNA
For Maintainers
Overview
Vulnerabilities in Plugins
Jenkins Security Team
About
Contributions
This advisory announces vulnerabilities in the following Jenkins deliverables:
Avatar
Plugin
Build Pipeline
Plugin
Codefresh Integration
Plugin
Configuration as Code
Plugin
eggplant-plugin
Plugin
File System SCM
Plugin
Google Cloud Messaging Noti
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-08-07
Published