Data Modification Vulnerability in Jenkins Job Import Plugin by Jenkins
CVE-2019-1003017
5.3MEDIUM
Summary
A data modification vulnerability exists in the Jenkins Job Import Plugin, allowing unauthorized copying of jobs from another Jenkins instance. This can lead to the installation of additional necessary plugins to load the configuration of the imported jobs, potentially compromising the security of the Jenkins environment.
Affected Version(s)
Jenkins Job Import Plugin 3.0 and earlier
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability Reserved
Vulnerability published