CVE-2019-10302: High severity jenkins vulnerability
Jenkins jira-ext Plugin 0.8 and earlier stored credentials unencrypted in its global configuration file hudson.plugins.jira.JiraProjectProperty.xml on the Jenkins master. These credentials could be viewed by users with access to the Jenkins master file system.
jira-ext Plugin version 0.9 stores credentials encrypted.
Other sources
Jenkins jira-ext Plugin 0.8 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10302?
CVE-2019-10302 is classified as a medium severity vulnerability.
How do I fix CVE-2019-10302?
To fix CVE-2019-10302, update the jira-ext Plugin to version 0.9 or later.
What are the risks of CVE-2019-10302?
The risks of CVE-2019-10302 include unauthorized access to unencrypted credentials stored in the Jenkins master file system.
Which versions are affected by CVE-2019-10302?
CVE-2019-10302 affects jira-ext Plugin versions 0.8 and earlier.
Who is impacted by CVE-2019-10302?
Users or organizations using vulnerable versions of the Jenkins jira-ext Plugin are impacted by CVE-2019-10302.