Stored Token Exposure in Jenkins Mattermost Notification Plugin
CVE-2019-10459
6.5MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 23 October 2019
What is CVE-2019-10459?
The Jenkins Mattermost Notification Plugin versions up to 2.7.0 is susceptible to a vulnerability where webhook URLs containing sensitive tokens are stored unencrypted in the global configuration file and job config.xml files on the Jenkins master. This allows any user with Extended Read permission or file system access to the Jenkins master to view these tokens, potentially compromising the integrity and security of the associated services. Proper handling and encryption of sensitive information are essential to mitigate such vulnerabilities.
Affected Version(s)
Jenkins Mattermost Notification Plugin 2.7.0 and earlier