Sensitive Information Exposure in Jenkins OpenId Connect Authentication Plugin
CVE-2019-1003021
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 6 February 2019
What is CVE-2019-1003021?
An exposure of sensitive information vulnerability is present in the Jenkins OpenId Connect Authentication Plugin versions 1.4 and earlier. This flaw allows attackers who have access to the Jenkins administrator's web interface or who can manipulate the administrator's browser through malicious extensions to extract the configured client secret. This poses a significant risk, as the client secret is critical for authenticating the integration of external applications with Jenkins.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jenkins OpenId Connect Authentication Plugin 1.4 and earlier
References
CVSS V3.1
Timeline
Vulnerability Reserved
Vulnerability published