Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-87063.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-87063
Upstream
  • CVE-2019-10298
Published
2019-04-04T16:29:03Z
Modified
2026-08-31T05:26:07Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
CVE-2019-10298 affecting package koji 1.35.3-10
Details

Jenkins Koji Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

References

Affected packages

Azure Linux:3 / koji

Package

Name
koji
Purl
pkg:rpm/azure-linux/koji

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
1.35.3-10

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-87063.json"