CVE-2019-10320

MEDIUM

Jenkins Credentials Plugin <2.1.18 - Info Disclosure

Title source: llm
STIX 2.1

Description

Jenkins Credentials Plugin 2.1.18 and earlier allowed users with permission to create or update credentials to confirm the existence of files on the Jenkins master with an attacker-specified path, and obtain the certificate content of files containing a PKCS#12 certificate.

References (7)

Core 7
Core References
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2019/05/21/1
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2019/May/39
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/108462
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHBA-2019:1605
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:1636
Mitigation, Vendor Advisory x_refsource_confirm
https://jenkins.io/security/advisory/2019-05-21/#SECURITY-1322

Scores

CVSS v3 4.3
EPSS 0.0096
EPSS Percentile 56.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-538
Status published
Products (2)
jenkins/credentials < 2.1.18
org.jenkins-ci.plugins/credentials 0 - 2.1.19Maven
Published May 21, 2019
Tracked Since Feb 18, 2026