Credentials Management Flaw in Jenkins Koji Plugin by CloudBees
CVE-2019-10298
What is CVE-2019-10298?
The Jenkins Koji Plugin contains a significant flaw that allows for the insecure storage of sensitive credentials within its global configuration file on the Jenkins master. This unencrypted storage means that users with access to the master file system can easily view these credentials, posing a risk of unauthorized access and potential exploitation. It is essential for users of the Jenkins Koji Plugin to recognize this vulnerability and take appropriate measures to secure their systems and sensitive data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jenkins Koji Plugin all versions as of 2019-04-03
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved