CVE-2019-10450

Severity
3.3LOW
EPSS
0.0%
top 99.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 16
Latest updateMay 24

Description

Jenkins ElasticBox CI Plugin stores credentials unencrypted in the global config.xml configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 1.8 | Impact: 1.4

Affected Packages3 packages

🔴Vulnerability Details

3
GHSA
Cleartext Storage of Sensitive Information in Jenkins ElasticBox CI Plugin2022-05-24
OSV
Cleartext Storage of Sensitive Information in Jenkins ElasticBox CI Plugin2022-05-24
CVEList
CVE-2019-10450: Jenkins ElasticBox CI Plugin stores credentials unencrypted in the global config2019-10-16

📋Vendor Advisories

1
Jenkins
Jenkins Security Advisory 2019-10-162019-10-16
CVE-2019-10450 (LOW CVSS 3.3) | Jenkins ElasticBox CI Plugin stores | cvebase.io