Configuration As Code
Vendor:
First CVE: Jun 26, 2018 · Active for 8 years
9
Total CVEs
More Total CVEs than 86% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
5.5
Avg CVSS
Higher Avg CVSS than 14% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Configuration As Code over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 26, 2018
8 years ago
Most Recent CVE
Jan 12, 2022
1,654 days ago
CVE Severity & Scoring
Configuration As Code9 CVEs
11%
78%
11%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local3 (33.3%)
Network6 (66.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low7 (77.8%)
High1 (11.1%)
None1 (11.1%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1000610HIGH A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in DataBoundConfigurator.java, Attribute.java, BaseConfigurat | Jun 26, 2018 | 8.8 | 25 | NO | NO |
CVE-2022-23106MEDIUM Jenkins Configuration as Code Plugin 1.55 and earlier used a non-constant time comparison function when validating an authentication token allowing attackers to use statistical met | Jan 12, 2022 | 5.3 | 20 | NO | NO |
CVE-2018-1000609MEDIUM A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in ConfigurationAsCode.java that allows attackers with Overal | Jun 26, 2018 | 6.5 | 20 | NO | NO |
CVE-2019-10362MEDIUM Jenkins Configuration as Code Plugin 1.24 and earlier did not escape values resulting in variable interpolation during configuration import when exporting, allowing attackers with | Jul 31, 2019 | 5.4 | 19 | NO | NO |
CVE-2019-10367MEDIUM Due to an incomplete fix of CVE-2019-10343, Jenkins Configuration as Code Plugin 1.26 and earlier did not properly apply masking to some values expected to be hidden when logging t | Aug 7, 2019 | 5.5 | 18 | NO | NO |
CVE-2019-10363MEDIUM Jenkins Configuration as Code Plugin 1.24 and earlier did not reliably identify sensitive values expected to be exported in their encrypted form. | Jul 31, 2019 | 4.9 | 18 | NO | NO |
CVE-2019-10345MEDIUM Jenkins Configuration as Code Plugin 1.20 and earlier did not treat the proxy password as a secret to be masked when logging or encrypted for export. | Jul 31, 2019 | 5.5 | 18 | NO | NO |
CVE-2019-10344MEDIUM Missing permission checks in Jenkins Configuration as Code Plugin 1.24 and earlier in various HTTP endpoints allowed users with Overall/Read access to access the generated schema a | Jul 31, 2019 | 4.3 | 17 | NO | NO |
Jenkins Configuration as Code Plugin 1.24 and earlier did not properly apply masking to values expected to be hidden when logging the configuration being applied. | Jul 31, 2019 | 3.3 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Configuration As Code
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 0.7 | 2 | 7.7 | 0.9% | 0 | 0 |
| 0.6 | 2 | 7.7 | 0.9% | 0 | 0 |
| 0.5 | 2 | 7.7 | 0.9% | 0 | 0 |
| 0.4 | 2 | 7.7 | 0.9% | 0 | 0 |
| 0.3 | 2 | 7.7 | 0.9% | 0 | 0 |
| 0.2 | 2 | 7.7 | 0.9% | 0 | 0 |
| 0.1 | 2 | 7.7 | 0.9% | 0 | 0 |