#VU21974 Information disclosure in Google OAuth Credentials - CVE-2019-10436
Published: October 21, 2019
Google OAuth Credentials
Jenkins
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the affected software allows the creation of credentials based on the content of files. A remote authenticated attacker with the permission to configure jobs and credentials can create a credential referencing an arbitrary file on the Jenkins master and obtain the contents of any file.