CVE-2019-10433: Jenkins dingding-notifications Cleartext Storage of Credentials Information Disclosure Vulnerability
Jenkins Dingding notifications Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
Other sources
Jenkins Dingding[??] Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
Jenkins Dingding[钉钉] Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
This vulnerability allows local attackers to disclose sensitive information on affected installations of Jenkins. Authentication is required to exploit this vulnerability. The specific flaw exists within the dingding-notifications plugin. The issue results from storing credentials in plaintext. An attacker can leverage this vulnerability to execute code in the context of the build process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10433?
CVE-2019-10433 is categorized as a high severity vulnerability due to the exposure of unencrypted credentials.
How do I fix CVE-2019-10433?
To fix CVE-2019-10433, update the Jenkins Dingding notifications Plugin to version 2.0.0 or later.
Which versions of the Jenkins Dingding notifications Plugin are affected by CVE-2019-10433?
Versions up to and including 1.9 of the Jenkins Dingding notifications Plugin are affected by CVE-2019-10433.
What types of permissions allow access to the vulnerable data in CVE-2019-10433?
Users with Extended Read permission or access to the Jenkins master file system can view the unencrypted credentials affected by CVE-2019-10433.
Can the credentials exposed in CVE-2019-10433 be protected?
Credentials in job config.xml files can be protected by properly managing user permissions on the Jenkins master system.