Information Exposure in Jenkins Azure VM Agents Plugin by Microsoft
CVE-2019-1003035

4.3MEDIUM

Key Information:

Vendor
Jenkins
Vendor
CVE Published:
8 March 2019

Summary

An information exposure vulnerability in the Jenkins Azure VM Agents Plugin allows users with Overall/Read permissions to exploit the 'verify configuration' functionality. This could enable attackers to gain access to sensitive information regarding the Azure configuration settings, potentially misusing this data for unauthorized access or other malicious purposes.

Affected Version(s)

Jenkins Azure VM Agents Plugin 0.8.0 and earlier

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.