CVE-2019-10362

MEDIUM

Jenkins Configuration as Code Plugin <1.24 - Info Disclosure

Title source: llm
STIX 2.1

Description

Jenkins Configuration as Code Plugin 1.24 and earlier did not escape values resulting in variable interpolation during configuration import when exporting, allowing attackers with permission to change Jenkins system configuration to obtain the values of environment variables.

References (2)

Core 2
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2019/07/31/1

Scores

CVSS v3 5.4
EPSS 0.0012
EPSS Percentile 30.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Details

CWE
CWE-116
Status published
Products (2)
io.jenkins/configuration-as-code 0 - 1.25Maven
jenkins/configuration_as_code < 1.24
Published Jul 31, 2019
Tracked Since Feb 18, 2026