#VU22028 Information disclosure in CRX Content Package Deployer - CVE-2019-10439
Published: October 22, 2019
CRX Content Package Deployer
Jenkins
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to missing permission check in various "doFillCredentialsIdItems" methods. A remote authenticated attacker with with Overall/Read permission can enumerate credentials ID of credentials stored in Jenkins.