CVE-2019-10370

MEDIUM

Jenkins Mask Passwords < 2.12.0 - Log Information Exposure

Title source: rule
STIX 2.1

Description

Jenkins Mask Passwords Plugin 2.12.0 and earlier transmits globally configured passwords in plain text as part of the configuration form, potentially resulting in their exposure.

References (2)

Core 2
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2019/08/07/1

Scores

CVSS v3 6.5
EPSS 0.0013
EPSS Percentile 31.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Details

CWE
CWE-532
Status published
Products (2)
jenkins/mask_passwords < 2.12.0
org.jenkins-ci.plugins/mask-passwords 0 - 2.13.0Maven
Published Aug 07, 2019
Tracked Since Feb 18, 2026