VulnerabilityModified
CVE-2019-10363
Jenkins Configuration as Code Plugin 1.24 and earlier did not reliably identify sensitive values expected to be exported in their encrypted form.
MEDIUM 4.9EPSS 0.61%
Does this matter?
Lower severity and a low EPSS score (0.61%). Track it; it rarely justifies an emergency change on its own.
Description
Jenkins Configuration as Code Plugin 1.24 and earlier did not reliably identify sensitive values expected to be exported in their encrypted form.
- CVSS 3.1
- 4.9 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.61% probability · 47th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-319
- Affected
- jenkins/configuration as code
- Source
- jenkinsci-cert@googlegroups.com
References
- http://www.openwall.com/lists/oss-security/2019/07/31/1Mailing List, Third Party Advisory
- https://jenkins.io/security/advisory/2019-07-31/#SECURITY-1458Vendor Advisory
- http://www.openwall.com/lists/oss-security/2019/07/31/1Mailing List, Third Party Advisory
- https://jenkins.io/security/advisory/2019-07-31/#SECURITY-1458Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.