CVE-2019-1003048

Source
https://nvd.nist.gov/vuln/detail/CVE-2019-1003048
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-1003048.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-1003048
Aliases
Published
2019-03-28T18:29:00Z
Modified
2024-09-03T02:21:16.114996Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A vulnerability in Jenkins PRQA Plugin 3.1.0 and earlier allows attackers with local file system access to the Jenkins home directory to obtain the unencrypted password from the plugin configuration.

References

Affected packages

Git / github.com/jenkinsci/prqa-plugin

Affected ranges

Type
GIT
Repo
https://github.com/jenkinsci/prqa-plugin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

0.*

0.2.0

1.*

1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2

2.*

2.0.10
2.0.11
2.0.12
2.0.9
2.1.0
2.1.0.RC09
2.1.0.RC10
2.1.0.RC11
2.1.0.RC12
2.1.0.RC13
2.1.0.RC14
2.1.0.RC15
2.1.0.RC16
2.1.0.RC17
2.1.0.RC18
2.1.0.RC19

Other

2_0_10-RELEASE
2_0_11-RELEASE
2_0_12-RELEASE
2_1_0-RC9
2_1_0-SNAPSHOT

prqa-plugin-0.*

prqa-plugin-0.2.0

prqa-plugin-1.*

prqa-plugin-1.0
prqa-plugin-1.0.1
prqa-plugin-1.0.2
prqa-plugin-1.0.3
prqa-plugin-1.0.4
prqa-plugin-1.0.5
prqa-plugin-1.1.0
prqa-plugin-1.1.1
prqa-plugin-1.1.2
prqa-plugin-1.1.3
prqa-plugin-1.2.0
prqa-plugin-1.2.1
prqa-plugin-1.2.2

prqa-plugin-2.*

prqa-plugin-2.0.10
prqa-plugin-2.0.11
prqa-plugin-2.0.12
prqa-plugin-2.0.9
prqa-plugin-2.1.0-rc9

prqa-plugin-3.*

prqa-plugin-3.1.0

v3.*

v3.0.0
v3.0.0-iteration.1
v3.0.0-iteration.2
v3.0.0-iteration.3
v3.0.0-iteration.4
v3.0.1
v3.1.0