PT-2019-11743 · Jenkins · Jenkins Configuration As Code Plugin+1
Mikaãl Barbero
·
Published
2019-07-31
·
Updated
2023-10-25
·
CVE-2019-10344
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Configuration as Code Plugin versions 1.24 and earlier
Description
The issue concerns missing permission checks in various HTTP endpoints, allowing users with Overall/Read access to access the generated schema and documentation for the plugin. This documentation contains detailed information about installed plugins.
Recommendations
For Jenkins Configuration as Code Plugin versions 1.24 and earlier, consider restricting access to the affected HTTP endpoints until a patch is available. As a temporary workaround, review and limit the Overall/Read access to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authorization
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jenkins
Jenkins Configuration As Code Plugin