PT-2018-9360 · Jenkins · Jenkins Black Duck Detect Plugin+1

Thomas De Grenier De Latour

·

Published

2018-06-05

·

Updated

2022-05-14

·

CVE-2018-1000191

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Black Duck Detect Plugin versions 1.4.0 and older
Description A sensitive information exposure issue exists, allowing attackers with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs, capturing credentials stored in Jenkins. The vulnerability is due to a lack of permission checks on methods implementing form validation, which also results in a CSRF vulnerability because these methods do not require POST requests.
Recommendations For Jenkins Black Duck Detect Plugin versions 1.4.0 and older, update the plugin to a version that requires Overall/Administer permissions for form validation methods and mandates POST requests to prevent CSRF attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1000191
GHSA-6W3H-VQ7M-V3QF

Affected Products

Jenkins
Jenkins Black Duck Detect Plugin