CVE-2019-1003021: Infoleak
An exposure of sensitive information vulnerability exists in Jenkins OpenId Connect Authentication Plugin 1.4 and earlier in OicSecurityRealm/config.jelly that allows attackers able to view a Jenkins administrator's web browser output, or control the browser (e.g. malicious extension) to retrieve the configured client secret.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1003021?
CVE-2019-1003021 is classified as a high severity vulnerability due to the potential exposure of sensitive information.
How do I fix CVE-2019-1003021?
To mitigate CVE-2019-1003021, upgrade the Jenkins OpenId Connect Authentication Plugin to version 1.5 or later.
What software is affected by CVE-2019-1003021?
CVE-2019-1003021 affects Jenkins OpenId Connect Authentication Plugin versions 1.4 and earlier.
What type of vulnerability is CVE-2019-1003021?
CVE-2019-1003021 is an exposure of sensitive information vulnerability.
What can an attacker do with CVE-2019-1003021?
An attacker with control of a Jenkins administrator's web browser can retrieve sensitive information through this vulnerability.