CVE-2019-10363
4.9MEDIUM
Key Information:
- Vendor
- Jenkins
- Vendor
- CVE Published:
- 31 July 2019
Summary
Jenkins Configuration as Code Plugin 1.24 and earlier did not reliably identify sensitive values expected to be exported in their encrypted form.
Affected Version(s)
Jenkins Configuration as Code Plugin 1.24 and earlier
References
CVSS V3.1
Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved