Vulnerability Description
Jenkins Configuration as Code Plugin 1.24 and earlier did not reliably identify sensitive values expected to be exported in their encrypted form.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jenkins | Configuration As Code | <= 1.24 |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2019/07/31/1Mailing ListThird Party Advisory
- https://jenkins.io/security/advisory/2019-07-31/#SECURITY-1458Vendor Advisory
- http://www.openwall.com/lists/oss-security/2019/07/31/1Mailing ListThird Party Advisory
- https://jenkins.io/security/advisory/2019-07-31/#SECURITY-1458Vendor Advisory
FAQ
What is CVE-2019-10363?
CVE-2019-10363 is a vulnerability with a CVSS score of 4.9 (MEDIUM). Jenkins Configuration as Code Plugin 1.24 and earlier did not reliably identify sensitive values expected to be exported in their encrypted form.
How severe is CVE-2019-10363?
CVE-2019-10363 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-10363?
Check the references section above for vendor advisories and patch information. Affected products include: Jenkins Configuration As Code.