CVE-2019-10320
jenkins-credentials-plugin: Certificate file read vulnerability in Credentials Plugin (SECURITY-1322)
Severity Score
4.3
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Jenkins Credentials Plugin 2.1.18 and earlier allowed users with permission to create or update credentials to confirm the existence of files on the Jenkins master with an attacker-specified path, and obtain the certificate content of files containing a PKCS#12 certificate.
Jenkins Credentials Plugin 2.1.18 y versiones anteriores permitieron a los usuarios con permiso crear o actualizar credenciales para confirmar la existencia de archivos en el maestro Jenkins con una attacker-specified path y obtener el contenido del certificado de los archivos que contienen un PKCS # 12 certificate.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2019-03-29 CVE Reserved
- 2019-05-21 CVE Published
- 2024-05-14 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-522: Insufficiently Protected Credentials
- CWE-538: Insertion of Sensitive Information into Externally-Accessible File or Directory
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
http://seclists.org/fulldisclosure/2019/May/39 | Mailing List | |
http://www.openwall.com/lists/oss-security/2019/05/21/1 | Mailing List | |
http://www.securityfocus.com/bid/108462 | Vdb Entry | |
https://wwws.nightwatchcybersecurity.com/2019/05/23/exploring-the-file-system-via-jenkins-credentials-plugin-vulnerability-cve-2019-10320 | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/errata/RHBA-2019:1605 | 2023-10-25 | |
https://access.redhat.com/errata/RHSA-2019:1636 | 2023-10-25 | |
https://jenkins.io/security/advisory/2019-05-21/#SECURITY-1322 | 2023-10-25 | |
https://access.redhat.com/security/cve/CVE-2019-10320 | 2019-07-03 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1714054 | 2019-07-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Jenkins Search vendor "Jenkins" | Credentials Search vendor "Jenkins" for product "Credentials" | <= 2.1.18 Search vendor "Jenkins" for product "Credentials" and version " <= 2.1.18" | jenkins |
Affected
|