CVE-2019-10320
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 1.0%
exploitation probability
1.0%top 40% of all CVEs
observed exploitation
nono source reports it
Jenkins Credentials Plugin 2.1.18 and earlier allowed users with permission to create or update credentials to confirm the existence of files on the Jenkins master with an attacker-specified path, and obtain the certificate content of files containing a PKCS#12 certificate.
Affected products
Jenkins project · Jenkins Credentials PluginReferences
https://access.redhat.com/errata/RHBA-2019:1605https://access.redhat.com/errata/RHSA-2019:1636http://seclists.org/fulldisclosure/2019/May/39https://jenkins.io/security/advisory/2019-05-21/#SECURITY-1322https://wwws.nightwatchcybersecurity.com/2019/05/23/exploring-the-file-system-via-jenkins-credentials-plugin-vulnerability-cve-2019-10320/http://www.openwall.com/lists/oss-security/2019/05/21/1http://www.securityfocus.com/bid/108462