PT-2019-14707 · Jenkins · Jenkins Gerrit Trigger Plugin+1

Daniel Beck

·

Published

2019-12-17

·

Updated

2023-10-25

·

CVE-2019-16552

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Gerrit Trigger Plugin versions 2.30.1 and earlier
Description A missing permission check in the plugin allows attackers with Overall/Read permission to connect to an attacker-specified HTTP URL or SSH server using attacker-specified credentials. This also enables them to determine the existence of a file with a given path on the Jenkins master.
Recommendations For versions 2.30.1 and earlier, update to a version that includes the fix for the missing permission check to prevent unauthorized access and file existence disclosure.

Fix

Improper Authorization

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2019-16552
GHSA-4R39-F4RH-J6Q8

Affected Products

Jenkins
Jenkins Gerrit Trigger Plugin