Vulnerability Details CVE-2019-16568
Jenkins SCTMExecutor Plugin 2.2 and earlier transmits previously configured service credentials in plain text as part of the global configuration, as well as individual jobs' configurations.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 5.6%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 5.0
Products affected by CVE-2019-16568
-
cpe:2.3:a:jenkins:sctmexecutor:0.1
-
cpe:2.3:a:jenkins:sctmexecutor:0.3
-
cpe:2.3:a:jenkins:sctmexecutor:0.4
-
cpe:2.3:a:jenkins:sctmexecutor:0.5
-
cpe:2.3:a:jenkins:sctmexecutor:0.6
-
cpe:2.3:a:jenkins:sctmexecutor:1.0
-
cpe:2.3:a:jenkins:sctmexecutor:1.1
-
cpe:2.3:a:jenkins:sctmexecutor:1.1.1
-
cpe:2.3:a:jenkins:sctmexecutor:1.2
-
cpe:2.3:a:jenkins:sctmexecutor:1.5
-
cpe:2.3:a:jenkins:sctmexecutor:1.5.1
-
cpe:2.3:a:jenkins:sctmexecutor:2.0
-
cpe:2.3:a:jenkins:sctmexecutor:2.2