PT-2019-14726 · Jenkins · Jenkins Rapiddeploy Plugin+1

·

CVE-2019-16571

·

Published

2019-12-17

·

Updated

2023-10-25

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins RapidDeploy Plugin versions 4.1 and earlier
Description A missing permission check in the plugin allows attackers with Overall/Read permission to connect to an attacker-specified web server.
Recommendations For Jenkins RapidDeploy Plugin versions 4.1 and earlier, update to a version that includes the necessary permission checks to prevent unauthorized connections.

Fix

Missing Authorization

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-16571
GHSA-M4VQ-V7HW-7FQQ

Affected Products

Jenkins
Jenkins Rapiddeploy Plugin