PT-2019-11743 · Jenkins · Jenkins Configuration As Code Plugin+1

Mikaãl Barbero

·

Published

2019-07-31

·

Updated

2023-10-25

·

CVE-2019-10344

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Configuration as Code Plugin versions 1.24 and earlier
Description The issue concerns missing permission checks in various HTTP endpoints, allowing users with Overall/Read access to access the generated schema and documentation for the plugin. This documentation contains detailed information about installed plugins.
Recommendations For Jenkins Configuration as Code Plugin versions 1.24 and earlier, consider restricting access to the affected HTTP endpoints until a patch is available. As a temporary workaround, review and limit the Overall/Read access to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2019-10344
GHSA-MQR8-3V8J-46WV

Affected Products

Jenkins
Jenkins Configuration As Code Plugin