CVE-2019-10343

LOW

Jenkins Configuration as Code Plugin < 1.24 - Sensitive Information Exposure in Log Files

Title source: llm
STIX 2.1

Description

Jenkins Configuration as Code Plugin 1.24 and earlier did not properly apply masking to values expected to be hidden when logging the configuration being applied.

References (2)

Core 2
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2019/07/31/1

Scores

CVSS v3 3.3
EPSS 0.0037
EPSS Percentile 28.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-532
Status published
Products (2)
io.jenkins/configuration-as-code 0 - 1.25Maven
jenkins/configuration_as_code < 1.24
Published Jul 31, 2019
Tracked Since Feb 18, 2026