PT-2019-11733 · Cloudbees+1 · Cloudbees Cd Plugin+2

Daniel Beck

·

Published

2019-06-11

·

Updated

2023-10-25

·

CVE-2019-10333

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins ElectricFlow Plugin version 1.1.5 and earlier CloudBees CD Plugin (affected versions not specified)
Description The issue concerns missing permission checks in various HTTP endpoints of the Jenkins ElectricFlow Plugin and form validation and autocompletion methods in the CloudBees CD Plugin. This allowed users with Overall/Read access to obtain sensitive information about the plugin configurations and connected ElectricFlow instances. The affected endpoints and methods have been updated to require Overall/Administer or Job/Configure permission.
Recommendations For Jenkins ElectricFlow Plugin version 1.1.5 and earlier, update the plugin to a version that includes the necessary permission checks. For CloudBees CD Plugin, ensure that the form validation and autocompletion methods are updated to require Overall/Administer or Job/Configure permission, as appropriate for the given method.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2019-10333
GHSA-M8F2-9282-X38V

Affected Products

Cloudbees Cd Plugin
Jenkins
Jenkins Electricflow Plugin