CVE-2019-10435 – org.jenkins-ci.plugins:vault-scm-plugin
Package
Manager: maven
Name: org.jenkins-ci.plugins:vault-scm-plugin
Vulnerable Version: >=0 <=1.1.1
Severity
Level: High
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00063 pctl0.19988
Details
Jenkins SourceGear Vault plugin transmits credentials in plain text Jenkins SourceGear Vault Plugin transmits configured credentials in plain text as part of job configuration forms, potentially resulting in their exposure. As of the publication of the advisory, there are no patches and the plugin is unmaintained.
Metadata
Created: 2022-05-24T16:57:28Z
Modified: 2022-12-06T21:07:51Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-jrmf-xhr6-3428/GHSA-jrmf-xhr6-3428.json
CWE IDs: ["CWE-319"]
Alternative ID: GHSA-jrmf-xhr6-3428
Finding: F332
Auto approve: 1