CVE-2019-10421

📊 4.3 MEDIUM0.1%🎯 0 exploits
📅 Published Sep 25, 2019
📋 Status: Modified

Jenkins Azure Event Grid Build Notifier Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.

🎯 Affected Products & Systems

1 product configurations affected

Filter by type:
Vulnerable
Version: ≤ 0.1
Target SW: jenkins
CPE:
cpe:2.3:a:jenkins:azure_event_grid_notifier:*:*:*:*:*:jenkins:*:*
Metrics
4.3 MEDIUMCVSS v3.1[email protected]
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector:
NETWORK
Complexity:
LOW
Privileges:
LOW
User Interaction:
NONE
Confidentiality:
LOW
Integrity:
NONE
Availability:
NONE
Scope:
UNCHANGED

🔍 Technical Details

Analysis Status
Modified
CVSS Details
4.3 (MEDIUM)v3.1
EPSS Details
0.1% (Minimal)17.6th percentile
Last updated: Oct 30, 2025
Exploitation probability within 30 days
Published Date
Sep 25, 2019 (6 years ago)
Last Modified
Nov 21, 2024 (11 months ago)
Security Weaknesses1
References3