CVE-2019-1003097 affects the Jenkins Crowd Integration Plugin, where it insecurely stores credentials unencrypted in the global config.xml file on the Jenkins master. This medium severity vulnerability (CVSS 6.5) allows authenticated users with file system access to the master to view sensitive credentials, posing a high confidentiality risk. There is no evidence of active exploitation, nor is public exploit code available, and it has garnered minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.2CPE matchmatch criteria | cpe:2.3:a:jenkins:crowd_integration:*:*:*:*:*:jenkins:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.