CVE-2019-10281: High severity jenkins relution enterprise appstore publisher vulnerability
Jenkins Relution Enterprise Appstore Publisher Plugin stores credentials unencrypted in its global configuration file org.jenkinsci.plugins.relutionpublisher.configuration.global.StoreConfiguration.xml on the Jenkins controller. These credentials can be viewed by users with access to the Jenkins controller file system.
Other sources
Jenkins Relution Enterprise Appstore Publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-10281.
What is the title of this vulnerability?
The title of this vulnerability is Jenkins Relution Enterprise Appstore Publisher Plugin stores credentials unencrypted in its global c…
What is the severity of CVE-2019-10281?
The severity of CVE-2019-10281 is high, with a severity value of 8.8.
What software is affected by CVE-2019-10281?
Jenkins Relution Enterprise Appstore Publisher Plugin version 1.24 is affected by CVE-2019-10281.
How can this vulnerability be exploited?
This vulnerability can be exploited by users with access to the Jenkins controller to view the unencrypted credentials stored in the global configuration file.