Sensitive Information Exposure in Jenkins OpenId Connect Authentication Plugin
CVE-2019-1003021
4.3MEDIUM
Key Information:
- Vendor
- Jenkins
- Vendor
- CVE Published:
- 6 February 2019
Summary
An exposure of sensitive information vulnerability is present in the Jenkins OpenId Connect Authentication Plugin versions 1.4 and earlier. This flaw allows attackers who have access to the Jenkins administrator's web interface or who can manipulate the administrator's browser through malicious extensions to extract the configured client secret. This poses a significant risk, as the client secret is critical for authenticating the integration of external applications with Jenkins.
Affected Version(s)
Jenkins OpenId Connect Authentication Plugin 1.4 and earlier
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability Reserved
Vulnerability published