Missing Permission Check in Jenkins VMware Lab Manager Slaves Plugin
CVE-2019-1003079
6.5MEDIUM
Key Information:
- Vendor
- Jenkins
- Vendor
- CVE Published:
- 4 April 2019
Summary
A vulnerability exists in the Jenkins VMware Lab Manager Slaves Plugin that stems from a missing permission check in the form validation method. This flaw allows attackers with Overall/Read permissions to initiate connections to arbitrary servers, potentially compromising the integrity and security of the Jenkins environment.
Affected Version(s)
Jenkins VMware Lab Manager Slaves Plugin all versions as of 2019-04-03
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved