CVE-2019-10460Insufficiently Protected Credentials in Jenkins Bitbucket Oauth

Severity
7.8HIGHNVD
EPSS
0.0%
top 98.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 23
Latest updateMay 24

Description

Jenkins Bitbucket OAuth Plugin 0.9 and earlier stored credentials unencrypted in the global config.xml configuration file on the Jenkins master where they could be viewed by users with access to the master file system.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

3
OSV
Jenkins Bitbucket OAuth Plugin contains Insufficiently Protected Credentials2022-05-24
GHSA
Jenkins Bitbucket OAuth Plugin contains Insufficiently Protected Credentials2022-05-24
CVEList
CVE-2019-10460: Jenkins Bitbucket OAuth Plugin 02019-10-23

📋Vendor Advisories

1
Jenkins
Jenkins Security Advisory 2019-10-232019-10-23
CVE-2019-10460 — Insufficiently Protected Credentials | cvebase