PT-2019-11850 · Jenkins · Jenkins Oracle Cloud Infrastructure Compute Classic Plugin+1

Viktor Gazdag

·

Published

2019-10-16

·

Updated

2023-10-25

·

CVE-2019-10456

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Oracle Cloud Infrastructure Compute Classic Plugin (affected versions not specified)
Description A cross-site request forgery issue exists, allowing attackers to connect to a specified URL using specified credentials. The plugin does not perform permission checks on a method implementing form validation, enabling users with Overall/Read access to initiate a connection test to a specified server with a specified username and password. The form validation method is also vulnerable as it does not require POST requests.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Weakness Enumeration

Related Identifiers

CVE-2019-10456
GHSA-H668-P5HG-7MC5

Affected Products

Jenkins
Jenkins Oracle Cloud Infrastructure Compute Classic Plugin