Medium severity6.5NVD Advisory· Published Jul 19, 2019· Updated Jun 17, 2026
CVE-2019-1010241
CVE-2019-1010241
Description
Jenkins Credentials Binding Plugin Jenkins 1.17 is affected by: CWE-257: Storing Passwords in a Recoverable Format. The impact is: Authenticated users can recover credentials. The component is: config-variables.jelly line #30 (passwordVariable). The attack vector is: Attacker creates and executes a Jenkins job.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:jenkins:credentials_binding:1.17:*:*:*:*:jenkins:*:*
- Jenkins Credentials Binding Plugin/Jenkinsv5Range: 1.17
Patches
Vulnerability mechanics
References
5- docs.google.com/document/d/1MBEoJSMvkjp5Kua0bRD_kiDBisL0fOCwTL9uMWj4lGA/editnvdExploitThird Party AdvisoryWEB
- www.securityfocus.com/bid/109320nvdThird Party AdvisoryVDB Entry
- github.com/advisories/GHSA-j7gw-mwfg-vqf4ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-1010241ghsaADVISORY
- web.archive.org/web/20200227030005/https://www.securityfocus.com/bid/109320ghsaWEB
News mentions
0No linked articles in our index yet.