PT-2019-14714 · Jenkins · Jenkins Websphere Deployer Plugin+1

·

CVE-2019-16559

·

Publicado

2019-12-17

·

Atualizado

2023-10-25

CVSS v2.0

5.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Jenkins WebSphere Deployer Plugin versions 1.6.1 and earlier
Description A missing permission check in the plugin allows attackers with Overall/Read permission to perform connection tests and determine whether files with an attacker-specified path exist on the Jenkins master file system. The plugin also does not perform permission checks in methods performing form validation, allowing users with Overall/Read access to obtain limited information about the Jenkins and plugin configuration. Furthermore, the form validation methods are vulnerable to CSRF attacks as they do not require POST requests.
Recommendations For Jenkins WebSphere Deployer Plugin versions 1.6.1 and earlier, as a temporary workaround, consider restricting access to the plugin's form validation methods to minimize the risk of exploitation. Additionally, restrict the ability to perform connection tests and set plugin configuration options to authorized users only. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Default Permissions

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-16559
GHSA-MXF8-GRM7-MVQW

Produtos afetados

Jenkins
Jenkins Websphere Deployer Plugin