CVE-2019-10459
Jenkins Mattermost Notification Plugin 2.7.0 and earlier stored webhook URLs containing a secret token unencrypted in its global configuration file and job config.xml files on the Jenkins master where they could be viewed by users with Extended Read…
Does this matter?
Lower severity and a low EPSS score (0.93%). Track it; it rarely justifies an emergency change on its own.
Description
Jenkins Mattermost Notification Plugin 2.7.0 and earlier stored webhook URLs containing a secret token unencrypted in its global configuration file and job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master file system.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.93% probability · 59th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-522
- Affected
- jenkins/mattermost notification
- Source
- jenkinsci-cert@googlegroups.com
References
- http://www.openwall.com/lists/oss-security/2019/10/23/2Mailing List, Third Party Advisory
- https://jenkins.io/security/advisory/2019-10-23/#SECURITY-1628Vendor Advisory
- http://www.openwall.com/lists/oss-security/2019/10/23/2Mailing List, Third Party Advisory
- https://jenkins.io/security/advisory/2019-10-23/#SECURITY-1628Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.