CVE-2019-1003039

Source
https://cve.org/CVERecord?id=CVE-2019-1003039
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-1003039.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-1003039
Aliases
Published
2019-03-08T21:29:00.670Z
Modified
2026-03-15T14:32:25.795368Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

An insufficiently protected credentials vulnerability exists in JenkinsAppDynamics Dashboard Plugin 1.0.14 and earlier in src/main/java/nl/codecentric/jenkins/appd/AppDynamicsResultsPublisher.java that allows attackers without permission to obtain passwords configured in jobs to obtain them.

References

Affected packages

Git / github.com/jenkinsci/appdynamics-plugin

Affected ranges

Type
GIT
Repo
https://github.com/jenkinsci/appdynamics-plugin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.0.14"
        }
    ]
}

Affected versions

appdynamics-dashboard-1.*
appdynamics-dashboard-1.0.0
appdynamics-dashboard-1.0.1
appdynamics-dashboard-1.0.10
appdynamics-dashboard-1.0.11
appdynamics-dashboard-1.0.12
appdynamics-dashboard-1.0.13
appdynamics-dashboard-1.0.14
appdynamics-dashboard-1.0.2
appdynamics-dashboard-1.0.3
appdynamics-dashboard-1.0.4
appdynamics-dashboard-1.0.5
appdynamics-dashboard-1.0.6
appdynamics-dashboard-1.0.7
appdynamics-dashboard-1.0.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-1003039.json"