CVE-2019-10362: Infoleak
Jenkins Configuration as Code Plugin 1.24 and earlier did not escape values resulting in variable interpolation during configuration import when exporting, allowing attackers with permission to change Jenkins system configuration to obtain the values of environment variables.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10362?
CVE-2019-10362 has a high severity rating due to potential exposure of sensitive configuration values.
How do I fix CVE-2019-10362?
To fix CVE-2019-10362, upgrade the Jenkins Configuration as Code Plugin to version 1.25 or later.
What is the impact of CVE-2019-10362?
The impact of CVE-2019-10362 allows attackers with permission to modify Jenkins configurations to leak the values of environment variables.
Which versions of Jenkins are affected by CVE-2019-10362?
CVE-2019-10362 affects Jenkins Configuration as Code Plugin versions 1.24 and earlier.
Is CVE-2019-10362 a remote or local vulnerability?
CVE-2019-10362 is a local vulnerability, requiring user permissions to exploit the configuration changes.