CVE-2019-10427

Description

Jenkins Aqua MicroScanner Plugin 1.0.7 and earlier transmitted configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.

Risk Information

Base Score
5.3
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
0.048

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2019-10427 are fixed in Jenkins - aqua-microscanner 1.0.8Windows
Vulnerabilities CVE-2019-10427 are fixed in Jenkins - aqua-microscanner for Linux 1.0.8Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234