cbcvebase.
CVE-2019-10367
published 2019-08-07

CVE-2019-10367: Due to an incomplete fix of CVE-2019-10343, Jenkins Configuration as Code Plugin 1.26 and earlier did not properly apply masking to some values expected to be…

PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.38%
30.3th percentile
Due to an incomplete fix of CVE-2019-10343, Jenkins Configuration as Code Plugin 1.26 and earlier did not properly apply masking to some values expected to be hidden when logging the configuration being applied.

Affected

18 ranges
VendorProductVersion rangeFixed in
jenkinsavatar_plugin
jenkinsbuild_pipeline_plugin
jenkinscodefresh_integration_plugin
jenkinsconfiguration_as_code<= 1.26
jenkinsconfiguration_as_code_plugin
jenkinsfile_system_scm_plugin
jenkinsgitlab_authentication_plugin
jenkinsgoogle_cloud_messaging_notification_plugin
jenkinsjclouds_plugin
jenkinsjenkins_instance_with_this_plugin
jenkinsmask_passwords_plugin
jenkinspegdown_formatter_plugin
jenkinsrelution_enterprise_appstore_publisher_plugin
jenkinssimple_travis_pipeline_runner_plugin
jenkinstestlink_plugin
jenkinsvmware_lab_manager_slaves_plugin
jenkinswall_display_master_project_plugin
jenkinsxl_testview_plugin

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.