Sensitive Value Exposure in Jenkins Configuration as Code Plugin
CVE-2019-10363
4.9MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 31 July 2019
What is CVE-2019-10363?
The Jenkins Configuration as Code Plugin prior to version 1.25 lacks proper validation for sensitive configuration values. As a result, sensitive values that should be encrypted may be exported in plain text, leading to potential exposure of sensitive information. This vulnerability raises significant security concerns for users who rely on the secure storage of sensitive configurations.
Affected Version(s)
Jenkins Configuration as Code Plugin 1.24 and earlier