CVE-2019-11350: Critical severity jenkins twitter vulnerability
Published Apr 19, 2019
·Updated
CloudBees Jenkins Operations Center 2.150.2.3, when an expired trial license exists, allows Cleartext Password Storage and Retrieval via the proxy configuration page.
Affected Software
1 affected component
cloudbees Jenkins Operations Center=2.150.2.3
Event History
Apr 19, 2019
CVE Published
via MITRE·08:07 PM
Data Sourced
via MITRE·08:07 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-11350?
CVE-2019-11350 is rated as a medium severity vulnerability.
2
What does CVE-2019-11350 exploit?
CVE-2019-11350 exploits cleartext password storage and retrieval due to an expired trial license.
3
How do I fix CVE-2019-11350?
To fix CVE-2019-11350, update CloudBees Jenkins Operations Center to a version later than 2.150.2.3.
4
Who is affected by CVE-2019-11350?
CVE-2019-11350 affects users of CloudBees Jenkins Operations Center version 2.150.2.3.
5
What can happen if CVE-2019-11350 is exploited?
If CVE-2019-11350 is exploited, attackers may gain unauthorized access to sensitive credentials stored in cleartext.