CVE-2019-1003039

Source
https://nvd.nist.gov/vuln/detail/CVE-2019-1003039
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-1003039.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-1003039
Aliases
Published
2019-03-08T21:29:00Z
Modified
2024-09-03T02:21:12.972283Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

An insufficiently protected credentials vulnerability exists in JenkinsAppDynamics Dashboard Plugin 1.0.14 and earlier in src/main/java/nl/codecentric/jenkins/appd/AppDynamicsResultsPublisher.java that allows attackers without permission to obtain passwords configured in jobs to obtain them.

References

Affected packages

Git / github.com/jenkinsci/appdynamics-plugin

Affected ranges

Type
GIT
Repo
https://github.com/jenkinsci/appdynamics-plugin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

appdynamics-dashboard-1.*

appdynamics-dashboard-1.0.0
appdynamics-dashboard-1.0.1
appdynamics-dashboard-1.0.10
appdynamics-dashboard-1.0.11
appdynamics-dashboard-1.0.12
appdynamics-dashboard-1.0.13
appdynamics-dashboard-1.0.14
appdynamics-dashboard-1.0.2
appdynamics-dashboard-1.0.3
appdynamics-dashboard-1.0.4
appdynamics-dashboard-1.0.5
appdynamics-dashboard-1.0.6
appdynamics-dashboard-1.0.7
appdynamics-dashboard-1.0.9