CVE-2019-10288 describes a vulnerability in the Jenkins Jabber Server Plugin where credentials are stored unencrypted in the global configuration file on the Jenkins master, making them accessible to users with file system access. This vulnerability carries a high CVSS score of 8.8, indicating a significant risk due to its low attack complexity and potential for high impact on confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the unencrypted storage of credentials presents a clear security risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:jenkins:jabber_server:*:*:*:*:*:jenkins:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.