CVE-2019-10345: Medium severity jenkins configuration as code vulnerability
Jenkins Configuration as Code Plugin 1.20 and earlier did not treat the proxy password as a secret to be masked when logging or encrypted for export.
Other sources
Jenkins Configuration as Code Plugin prior to version 1.25 did not treat the proxy password as a secret to be masked when logging or encrypted for export.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10345?
CVE-2019-10345 has a severity rating of medium due to the risk of exposing sensitive proxy password information.
How do I fix CVE-2019-10345?
To fix CVE-2019-10345, upgrade the Jenkins Configuration as Code Plugin to version 1.25 or later.
What versions are affected by CVE-2019-10345?
CVE-2019-10345 affects Jenkins Configuration as Code Plugin versions 1.20 and earlier.
What data is exposed in CVE-2019-10345?
CVE-2019-10345 potentially exposes the proxy password in logs and during export, which should be treated as a secret.
Is CVE-2019-10345 a remote vulnerability?
CVE-2019-10345 is considered a local vulnerability, as it requires access to the Jenkins environment to exploit.