Sensitive Information Exposure in Jenkins OpenId Connect Authentication Plugin
CVE-2019-1003021
4.3MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 6 February 2019
What is CVE-2019-1003021?
An exposure of sensitive information vulnerability is present in the Jenkins OpenId Connect Authentication Plugin versions 1.4 and earlier. This flaw allows attackers who have access to the Jenkins administrator's web interface or who can manipulate the administrator's browser through malicious extensions to extract the configured client secret. This poses a significant risk, as the client secret is critical for authenticating the integration of external applications with Jenkins.
Affected Version(s)
Jenkins OpenId Connect Authentication Plugin 1.4 and earlier