CVE-2019-10436
Improper Limitation of a Pathname to a Restricted Directory in Jenkins Google OAuth Credentials Plugin
6.5
MEDIUM
CVSS 3.1
EPSS 0.15%
Description
An arbitrary file read vulnerability in Jenkins Google OAuth Credentials Plugin 0.9 and earlier allowed attackers able to configure jobs and credentials in Jenkins to obtain the contents of any file on the Jenkins master.
How to fix CVE-2019-10436
To remediate CVE-2019-10436, upgrade the affected package to a fixed version below.
- —upgrade to 0.10 or later
Is CVE-2019-10436 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 0.10
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |