File Disclosure Vulnerability in Jenkins Credentials Plugin
CVE-2019-10320
What is CVE-2019-10320?
The Jenkins Credentials Plugin versions 2.1.18 and prior are susceptible to a file disclosure vulnerability. This allows authorized users to probe the Jenkins master filesystem, confirming the existence of files at specified paths. Furthermore, attackers can extract sensitive certificate data, particularly PKCS#12 certificates, which could lead to unauthorized access and further exploits within the Jenkins environment. It is critical for users to update to a later version to mitigate this risk and protect sensitive information.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jenkins Credentials Plugin 2.1.18 and earlier
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved