cbcvebase.
CVE-2019-10430
published 2019-09-25

CVE-2019-10430: Jenkins NeuVector Vulnerability Scanner Plugin 1.5 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they…

medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
Jenkins NeuVector Vulnerability Scanner Plugin 1.5 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
jenkinsapplication_director_plugin
jenkinsaqua_microscanner_plugin
jenkinsaqua_security_scanner_plugin
jenkinsassembla_plugin
jenkinsazure_event_grid_build_notifier_plugin
jenkinscall_remote_job_plugin
jenkinscd_plugin
jenkinscodescan_plugin
jenkinsgem_publisher_plugin
jenkinsgit_changelog_plugin
jenkinsgitlab_logo_plugin
jenkinsgoogle_calendar_plugin
jenkinsinedo_buildmaster_plugin
jenkinsinedo_proget_plugin
jenkinsjenkins_core
jenkinsjenkins_instance_with_this_plugin
jenkinsjenkins_lts
jenkinsjenkins_weekly
jenkinskubernetes_pipeline_arquillian_steps_plugin
jenkinskubernetes_pipeline_kubernetes_steps_plugin
jenkinslog_parser_plugin
jenkinsmask_password_plugin
jenkinsmask_passwords_plugin
jenkinsneuvector_vulnerability_scanner<= 1.5
jenkinsproject_inheritance_plugin