CVE-2019-10436

An arbitrary file read vulnerability in Jenkins Google OAuth Credentials Plugin 0.9 and earlier allowed attackers able to configure jobs and credentials in Jenkins to obtain the contents of any file on the Jenkins master.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jenkins:google_oauth_credentials:*:*:*:*:*:jenkins:*:*

History

21 Nov 2024, 04:19

Type Values Removed Values Added
References () https://jenkins.io/security/advisory/2019-10-16/#SECURITY-1583 - Vendor Advisory () https://jenkins.io/security/advisory/2019-10-16/#SECURITY-1583 - Vendor Advisory

Information

Published : 2019-10-16 14:15

Updated : 2024-11-21 04:19


NVD link : CVE-2019-10436

Mitre link : CVE-2019-10436

CVE.ORG link : CVE-2019-10436


JSON object : View

Products Affected

jenkins

  • google_oauth_credentials