An arbitrary file read vulnerability in Jenkins Google OAuth Credentials Plugin 0.9 and earlier allowed attackers able to configure jobs and credentials in Jenkins to obtain the contents of any file on the Jenkins master.
References
Link | Resource |
---|---|
https://jenkins.io/security/advisory/2019-10-16/#SECURITY-1583 | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: jenkins
Published: 2019-10-16T13:00:44
Updated: 2023-10-24T16:49:35.976Z
Reserved: 2019-03-29T00:00:00
Link: CVE-2019-10436
JSON object: View
NVD Information
Status : Modified
Published: 2019-10-16T14:15:11.277
Modified: 2023-10-25T18:16:23.333
Link: CVE-2019-10436
JSON object: View
Redhat Information
No data.
CWE