CVE-2019-10370

MEDIUM

Jenkins Mask Passwords Plugin < 2.12.0 - Plaintext Password Exposure in Configuration Form

Title source: llm
STIX 2.1

Description

Jenkins Mask Passwords Plugin 2.12.0 and earlier transmits globally configured passwords in plain text as part of the configuration form, potentially resulting in their exposure.

References (2)

Core 2
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2019/08/07/1

Scores

CVSS v3 6.5
EPSS 0.0130
EPSS Percentile 66.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Details

CWE
CWE-532
Status published
Products (2)
jenkins/mask_passwords < 2.12.0
org.jenkins-ci.plugins/mask-passwords 0 - 2.13.0Maven
Published Aug 07, 2019
Tracked Since Feb 18, 2026