356
VMScore

CVE-2019-1003061

Published: 04/04/2019 Updated: 25/10/2023
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

Jenkins jenkins-cloudformation-plugin Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jenkins jenkins-cloudformation-plugin

Github Repositories

A Jenkins build wrapper to spawn cloud formation stacks in amazon before running a build and delete them at the end.

Jenkins CloudFormation Plugin This is a Jenkins plugin for creating, using, and deleting AWS CloudFormation stacks in your environment Before using this plugin, please make sure you're familiar with understanding pricing for the AWS resources that you create with AWS CloudFormation Using the plugin You can use this plugin: as a wrapper (before and after the build) as a