CVE-2019-10476: High severity jenkins vulnerability
Published Oct 23, 2019
·Updated
Jenkins Zulip Plugin 1.1.0 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.
Affected Software
1 affected component
Jenkins Zulip Jenkins<=1.1.0
Event History
Oct 23, 2019
CVE Published
via MITRE·12:45 PM
Data Sourced
via MITRE·12:45 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-10476?
CVE-2019-10476 has a severity rating of high due to the exposure of unencrypted credentials.
2
How do I fix CVE-2019-10476?
To fix CVE-2019-10476, upgrade the Jenkins Zulip Plugin to version 1.1.1 or later to ensure that credentials are stored securely.
3
Who is affected by CVE-2019-10476?
CVE-2019-10476 affects any Jenkins instance using Zulip Plugin version 1.1.0 or earlier.
4
What type of vulnerability is CVE-2019-10476?
CVE-2019-10476 is a security vulnerability related to credential storage that impacts Jenkins installations.
5
Can users exploit CVE-2019-10476?
Yes, users with access to the Jenkins master file system can exploit CVE-2019-10476 to view unencrypted credentials.