CVE-2019-10345: Jenkins Configuration As Code
Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Jenkins Configuration as Code Plugin 1.20 and earlier did not treat the proxy password as a secret to be masked when logging or encrypted for export.
Affected products
- Jenkins Configuration As Code: before 1.20 (fixed in 1.20)
Published 2019-07-31. Last modified 2026-06-17.