PT-2019-11821 · Jenkins · Jenkins Aqua Microscanner Plugin+1

James Holderness

·

Published

2019-09-25

·

Updated

2023-10-25

·

CVE-2019-10427

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Aqua MicroScanner Plugin version 1.0.7 and earlier
Description The issue involves the transmission of configured credentials in plain text as part of the global Jenkins configuration form, potentially leading to their exposure.
Recommendations For Jenkins Aqua MicroScanner Plugin version 1.0.7 and earlier, update to a version later than 1.0.7 to resolve the issue.

Fix

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2019-10427
GHSA-VV4Q-2W98-4V8G

Affected Products

Jenkins
Jenkins Aqua Microscanner Plugin