PT-2019-11730 · Jenkins · Jenkins Git Plugin
Published
2019-05-31
·
Updated
2023-10-25
·
CVE-2019-10330
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Gitea Plugin versions 1.1.1 and earlier
Description
The issue allows attackers without commit access to the Git repository to change Jenkinsfiles, even if Jenkins is configured to consider them untrusted. This is due to the lack of implementation of trusted revisions in the affected plugin versions.
Recommendations
For Jenkins Gitea Plugin versions 1.1.1 and earlier, update to version 1.1.2 or later to resolve the issue.
Fix
Missing Authorization
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jenkins Git Plugin