CVE-2019-10434: High severity jenkins vulnerability
Published Oct 1, 2019
·Updated
Jenkins LDAP Email Plugin transmits configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.
Affected Software
1 affected component
Jenkins Ldap Email Jenkins<=0.8
Event History
Oct 1, 2019
CVE Published
via MITRE·01:45 PM
Data Sourced
via MITRE·01:45 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-10434?
CVE-2019-10434 is classified as a medium severity vulnerability.
2
How does CVE-2019-10434 affect Jenkins LDAP Email Plugin users?
CVE-2019-10434 affects users by transmitting credentials in plain text, which may lead to unauthorized access.
3
How do I fix CVE-2019-10434?
To fix CVE-2019-10434, upgrade the Jenkins LDAP Email Plugin to version 0.9 or later.
4
What versions of Jenkins LDAP Email Plugin are affected by CVE-2019-10434?
Versions of Jenkins LDAP Email Plugin up to and including 0.8 are affected by CVE-2019-10434.
5
What should I do if I cannot immediately upgrade due to CVE-2019-10434?
If you cannot upgrade immediately due to CVE-2019-10434, consider reviewing and securing your configuration to minimize exposure.