CVE-2019-10319: Jenkins Pluggable Authentication Module

Medium severity, CVSS 4.3. EPSS: 0.8% chance of exploitation in the next 30 days.

A missing permission check in Jenkins PAM Authentication Plugin 1.5 and earlier, except 1.4.1 in PamSecurityRealm.DescriptorImpl#doTest allowed users with Overall/Read permission to obtain limited information about the file /etc/shadow and the user Jenkins is running as.

Affected products

  • Jenkins Pluggable Authentication Module: version 1.0 only; version 1.1 only; version 1.2 only; version 1.3 only; version 1.4 only; version 1.5 only

Published 2019-05-21. Last modified 2026-06-17.