CVE-2019-16568: Jenkins Sctmexecutor

Medium severity, CVSS 5.3. EPSS: 0.6% chance of exploitation in the next 30 days.

Jenkins SCTMExecutor Plugin 2.2 and earlier transmits previously configured service credentials in plain text as part of the global configuration, as well as individual jobs' configurations.

Affected products

  • Jenkins Sctmexecutor: up to and including 2.2

Published 2019-12-17. Last modified 2026-06-17.