CVE-2019-10428: Jenkins Aqua Security Scanner Plugin showed plain text password in configuration form
7.5
CVSS Score
3.1
Basic Information
CVE ID
GHSA ID
EPSS Score
0.26162%
CWE
Published
5/24/2022
Updated
1/30/2024
KEV Status
No
Technology
Java
Technical Details
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:aqua-security-scanner | maven | <= 3.0.17 | 3.0.18 |
Vulnerability Intelligence
Miggo AI
Root Cause Analysis
The vulnerable functions are likely those that handle the transmission of credentials in the global configuration form of the Aqua Security Scanner Plugin. The exact function names are inferred based on typical plugin structure and the nature of the vulnerability. The confidence level is medium because while we can infer the likely location and type of functions involved, the exact names and paths are not directly provided in the given information.