CVE-2019-10362
Jenkins Configuration as Code Plugin 1.24 and earlier did not escape values resulting in variable interpolation during configuration import when exporting, allowing attackers with permission to change Jenkins system configuration to obtain the values of…
Does this matter?
Lower severity and a low EPSS score (0.74%). Track it; it rarely justifies an emergency change on its own.
Description
Jenkins Configuration as Code Plugin 1.24 and earlier did not escape values resulting in variable interpolation during configuration import when exporting, allowing attackers with permission to change Jenkins system configuration to obtain the values of environment variables.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 0.74% probability · 52th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-116
- Affected
- jenkins/configuration as code
- Source
- jenkinsci-cert@googlegroups.com
References
- http://www.openwall.com/lists/oss-security/2019/07/31/1Mailing List, Third Party Advisory
- https://jenkins.io/security/advisory/2019-07-31/#SECURITY-1446Vendor Advisory
- http://www.openwall.com/lists/oss-security/2019/07/31/1Mailing List, Third Party Advisory
- https://jenkins.io/security/advisory/2019-07-31/#SECURITY-1446Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.