Data Modification Vulnerability in Jenkins Job Import Plugin by Jenkins
CVE-2019-1003017

5.3MEDIUM

Key Information:

Vendor
Jenkins
Vendor
CVE Published:
6 February 2019

Summary

A data modification vulnerability exists in the Jenkins Job Import Plugin, allowing unauthorized copying of jobs from another Jenkins instance. This can lead to the installation of additional necessary plugins to load the configuration of the imported jobs, potentially compromising the security of the Jenkins environment.

Affected Version(s)

Jenkins Job Import Plugin 3.0 and earlier

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.