PT-2019-11730 · Jenkins · Jenkins Git Plugin

Published

2019-05-31

·

Updated

2023-10-25

·

CVE-2019-10330

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Gitea Plugin versions 1.1.1 and earlier
Description The issue allows attackers without commit access to the Git repository to change Jenkinsfiles, even if Jenkins is configured to consider them untrusted. This is due to the lack of implementation of trusted revisions in the affected plugin versions.
Recommendations For Jenkins Gitea Plugin versions 1.1.1 and earlier, update to version 1.1.2 or later to resolve the issue.

Fix

Missing Authorization

Protection Mechanism Failure

Weakness Enumeration

Related Identifiers

CVE-2019-10330
GHSA-Q98C-RQX7-7GHF

Affected Products

Jenkins Git Plugin