Credential Storage Vulnerability in Jenkins Call Remote Job Plugin
CVE-2019-10422
6.5MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 25 September 2019
What is CVE-2019-10422?
The Jenkins Call Remote Job Plugin is susceptible to a vulnerability where it stores user credentials unencrypted within the job config.xml files on the Jenkins master. This design flaw allows any user with Extended Read permission or access to the underlying file system to view sensitive credentials, posing a significant security risk. Users are advised to review their configurations and consider encrypting credentials to safeguard against unauthorized access.
Affected Version(s)
Jenkins Call Remote Job Plugin 1.0.21 and earlier