PT-2019-11733 · Cloudbees+1 · Cloudbees Cd Plugin+2

·

CVE-2019-10333

·

Publicado

2019-06-11

·

Atualizado

2023-10-25

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins ElectricFlow Plugin version 1.1.5 and earlier CloudBees CD Plugin (affected versions not specified)
Description The issue concerns missing permission checks in various HTTP endpoints of the Jenkins ElectricFlow Plugin and form validation and autocompletion methods in the CloudBees CD Plugin. This allowed users with Overall/Read access to obtain sensitive information about the plugin configurations and connected ElectricFlow instances. The affected endpoints and methods have been updated to require Overall/Administer or Job/Configure permission.
Recommendations For Jenkins ElectricFlow Plugin version 1.1.5 and earlier, update the plugin to a version that includes the necessary permission checks. For CloudBees CD Plugin, ensure that the form validation and autocompletion methods are updated to require Overall/Administer or Job/Configure permission, as appropriate for the given method.

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-10333
GHSA-M8F2-9282-X38V

Produtos afetados

Cloudbees Cd Plugin
Jenkins
Jenkins Electricflow Plugin