PT-2019-4454 · Jenkins · Jenkins Jira Plugin+1

Daniel Beck

·

Published

2019-11-21

·

Updated

2023-10-25

·

CVE-2019-16541

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Jenkins JIRA Plugin versions 3.0.10 and earlier
Description The issue is related to the incorrect declaration of the scope for per-folder Jira site definitions, allowing users to select and use credentials with System scope. This can lead to unauthorized access to protected information. The problem is associated with insufficient restrictions on the controlled area of the system.
Recommendations For Jenkins JIRA Plugin versions 3.0.10 and earlier, update to version 3.0.11 or later, which defines the appropriate folder context for credential lookup. Note that existing per-folder Jira sites may lose access to already configured System-scoped credentials after the update.

Fix

Exposure of Resource to Wrong Sphere

Weakness Enumeration

Related Identifiers

BDU:2020-00241
CVE-2019-16541
GHSA-98M4-M2C3-QXGQ
RHSA-2020:3541
RHSA-2020:4297

Affected Products

Jenkins
Jenkins Jira Plugin