CVE-2019-16568 affects Jenkins SCTMExecutor Plugin versions 2.2 and earlier, allowing sensitive service credentials to be exposed in plaintext within global and job configurations. This vulnerability has a CVSS score of 5.3 (Medium), indicating a low-complexity attack requiring no authentication, which could lead to unauthorized disclosure of credentials. While the potential impact is data confidentiality loss, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.2CPE matchmatch criteria | cpe:2.3:a:jenkins:sctmexecutor:*:*:*:*:*:jenkins:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.