CVE-2019-10460: High severity jenkins bitbucket oauth vulnerability
Jenkins Bitbucket OAuth Plugin 0.9 and earlier stored credentials unencrypted in the global config.xml configuration file on the Jenkins master where they could be viewed by users with access to the master file system.
Other sources
Jenkins Bitbucket OAuth Plugin prior to 0.10 stores credentials unencrypted in the global config.xml configuration file on the Jenkins master where they could be viewed by users with access to the master file system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10460?
CVE-2019-10460 is considered a high severity vulnerability due to unencrypted storage of credentials.
How do I fix CVE-2019-10460?
To fix CVE-2019-10460, upgrade the Jenkins Bitbucket OAuth Plugin to version 0.10 or later.
What are the risks associated with CVE-2019-10460?
The risks associated with CVE-2019-10460 include unauthorized access to sensitive credentials by users who can access the Jenkins master file system.
Which versions of Jenkins Bitbucket OAuth Plugin are affected by CVE-2019-10460?
All versions of Jenkins Bitbucket OAuth Plugin up to and including 0.9 are affected by CVE-2019-10460.
What type of vulnerability is CVE-2019-10460 classified as?
CVE-2019-10460 is classified as a credential management vulnerability due to the unencrypted storage of sensitive data.