logo

CVE-2019-10435 org.jenkins-ci.plugins:vault-scm-plugin

Package

Manager: maven
Name: org.jenkins-ci.plugins:vault-scm-plugin
Vulnerable Version: >=0 <=1.1.1

Severity

Level: High

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

EPSS: 0.00063 pctl0.19988

Details

Jenkins SourceGear Vault plugin transmits credentials in plain text Jenkins SourceGear Vault Plugin transmits configured credentials in plain text as part of job configuration forms, potentially resulting in their exposure. As of the publication of the advisory, there are no patches and the plugin is unmaintained.

Metadata

Created: 2022-05-24T16:57:28Z
Modified: 2022-12-06T21:07:51Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-jrmf-xhr6-3428/GHSA-jrmf-xhr6-3428.json
CWE IDs: ["CWE-319"]
Alternative ID: GHSA-jrmf-xhr6-3428
Finding: F332
Auto approve: 1