CVE-2019-1003045

MEDIUM

Jenkins ECS Publisher Plugin <1.0.0 - Info Disclosure

Title source: llm

Description

A vulnerability in Jenkins ECS Publisher Plugin 1.0.0 and earlier allows attackers with Item/Extended Read permission, or local file system access to the Jenkins home directory to obtain the API token configured in this plugin's configuration.

Scores

CVSS v3 6.5
EPSS 0.0069
EPSS Percentile 71.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-522
Status published

Affected Products (2)

trustsource/ecs_publisher < 1.0.0
de.eacg/ecs-publisher < 1.0.1Maven

Timeline

Published Mar 28, 2019
Tracked Since Feb 18, 2026