CVE-2019-10318
Jenkins Azure AD Plugin stored the client secret unencrypted
3.3
LOW
CVSS 3.1
EPSS 1.8%
Description
Jenkins Azure AD Plugin stored the client secret unencrypted in the global config.xml configuration file on the Jenkins controller. These credentials could be viewed by users with access to the Jenkins controller file system. Azure AD Plugin now stores the client secret encrypted.
How to fix CVE-2019-10318
To remediate CVE-2019-10318, upgrade the affected package to a fixed version below.
- —upgrade to 0.3.4 or later
Is CVE-2019-10318 being exploited?
Low — EPSS is 1.8%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 0.3.4
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | LOW3.3 | CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |