{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-05-11T14:00:04.642","vulnerabilities":[{"cve":{"id":"CVE-2019-10438","sourceIdentifier":"jenkinsci-cert@googlegroups.com","published":"2019-10-16T14:15:11.840","lastModified":"2024-11-21T04:19:08.437","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A missing permission check in Jenkins CRX Content Package Deployer Plugin 1.8.1 and earlier allowed attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins."},{"lang":"es","value":"Una falta de comprobación de permiso en Jenkins CRX Content Package Deployer Plugin versión 1.8.1 y anteriores, permitía a atacantes con permiso General y de Lectura conectar con una URL especificada por el atacante usando los IDs de credenciales especificadas por el atacante obtenidas por medio de otro método, capturando así las credenciales almacenadas en Jenkins."}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:jenkins:crx_content_package_deployer:*:*:*:*:*:jenkins:*:*","versionEndIncluding":"1.8.1","matchCriteriaId":"91F42A23-CD9A-41E9-A728-9B34485301D1"}]}]}],"references":[{"url":"https://jenkins.io/security/advisory/2019-10-16/#SECURITY-1006%20%281%29","source":"jenkinsci-cert@googlegroups.com"},{"url":"https://jenkins.io/security/advisory/2019-10-16/#SECURITY-1006%20%281%29","source":"af854a3a-2127-422b-91ae-364da2661108"}]}}]}