CVE-2019-10370: Jenkins Mask Passwords

Medium severity, CVSS 6.5. EPSS: 1.3% chance of exploitation in the next 30 days.

Jenkins Mask Passwords Plugin 2.12.0 and earlier transmits globally configured passwords in plain text as part of the configuration form, potentially resulting in their exposure.

Affected products

  • Jenkins Mask Passwords: up to and including 2.12.0

Published 2019-08-07. Last modified 2026-06-17.