CVE-2019-10358

MEDIUM

Jenkins Maven Integration Plugin < 3.3 - Sensitive Information Exposure in Build Log

Title source: llm
STIX 2.1

Description

Jenkins Maven Integration Plugin 3.3 and earlier did not apply build log decorators to module builds, potentially revealing sensitive build variables in the build log.

References (2)

Core 2
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2019/07/31/1

Scores

CVSS v3 6.5
EPSS 0.0101
EPSS Percentile 58.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-532
Status published
Products (2)
jenkins/maven < 3.3
org.jenkins-ci.main/maven-plugin 0 - 3.4Maven
Published Jul 31, 2019
Tracked Since Feb 18, 2026