CVE-2019-1003097: Medium severity jenkins vulnerability
Published Apr 4, 2019
·Updated
Jenkins Crowd Integration Plugin stores credentials unencrypted in the global config.xml configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Affected Software
2 affected components
maven/com.ds.tools.hudson:crowd<=1.2
Jenkins Crowd Integration Jenkins<=1.2
Event History
Apr 4, 2019
CVE Published
via MITRE·03:38 PM
Data Sourced
via MITRE·03:38 PM
Description
May 13, 2022
Advisory Published
via GitHub·01:25 AM
Frequently Asked Questions
1
What is the severity of CVE-2019-1003097?
CVE-2019-1003097 has a high severity level due to the exposure of unencrypted credentials.
2
How do I fix CVE-2019-1003097?
To fix CVE-2019-1003097, update the Jenkins Crowd Integration Plugin to version 1.3 or later.
3
Who is affected by CVE-2019-1003097?
Users of the Jenkins Crowd Integration Plugin version 1.2 and below are affected by CVE-2019-1003097.
4
What does CVE-2019-1003097 allow an attacker to do?
CVE-2019-1003097 allows attackers with file system access to view unencrypted credentials stored in the Jenkins configuration file.
5
Is there a workaround for CVE-2019-1003097?
A workaround for CVE-2019-1003097 is to restrict file system access to the Jenkins master.