Sensitive Information Exposure in Jenkins OpenId Connect Authentication Plugin
CVE-2019-1003021

4.3MEDIUM

Key Information:

Vendor
Jenkins
Vendor
CVE Published:
6 February 2019

Summary

An exposure of sensitive information vulnerability is present in the Jenkins OpenId Connect Authentication Plugin versions 1.4 and earlier. This flaw allows attackers who have access to the Jenkins administrator's web interface or who can manipulate the administrator's browser through malicious extensions to extract the configured client secret. This poses a significant risk, as the client secret is critical for authenticating the integration of external applications with Jenkins.

Affected Version(s)

Jenkins OpenId Connect Authentication Plugin 1.4 and earlier

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.