CVE-2019-11350
CRITICALCloudBees Jenkins Operations Center <2.150.2.3 - Info Disclosure
Title source: llmDescription
CloudBees Jenkins Operations Center 2.150.2.3, when an expired trial license exists, allows Cleartext Password Storage and Retrieval via the proxy configuration page.
References (3)
Core 3
Core References
Third Party Advisory x_refsource_misc
https://raw.githubusercontent.com/binary1985/VulnerabilityDisclosure/master/CloudBees%20Jenkins%20Operations%20Center%20Password%20Disclosure
Release Notes x_refsource_confirm
https://release-notes.cloudbees.com/release/21/8.18
Scores
CVSS v3
9.8
EPSS
0.0034
EPSS Percentile
57.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-522
Status
published
Products (1)
cloudbees/jenkins_operations_center
2.150.2.3
Published
Apr 19, 2019
Tracked Since
Feb 18, 2026