PT-2019-14707 · Jenkins · Jenkins Gerrit Trigger Plugin+1
Daniel Beck
·
Published
2019-12-17
·
Updated
2023-10-25
·
CVE-2019-16552
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Gerrit Trigger Plugin versions 2.30.1 and earlier
Description
A missing permission check in the plugin allows attackers with Overall/Read permission to connect to an attacker-specified HTTP URL or SSH server using attacker-specified credentials. This also enables them to determine the existence of a file with a given path on the Jenkins master.
Recommendations
For versions 2.30.1 and earlier, update to a version that includes the fix for the missing permission check to prevent unauthorized access and file existence disclosure.
Fix
Improper Authorization
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jenkins
Jenkins Gerrit Trigger Plugin