Configuration Interpolation Issue in Jenkins by CloudBees
CVE-2019-10362
5.4MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 31 July 2019
What is CVE-2019-10362?
The Jenkins Configuration as Code Plugin versions 1.24 and earlier have a flaw where values are not properly escaped during configuration imports. This action can lead to variable interpolation, enabling attackers with sufficient permissions to manipulate the Jenkins system configuration and unlawfully access sensitive environment variable data.
Affected Version(s)
Jenkins Configuration as Code Plugin 1.24 and earlier