Missing Permission Check in Jenkins VMware Lab Manager Slaves Plugin
CVE-2019-1003079
6.5MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 4 April 2019
What is CVE-2019-1003079?
A vulnerability exists in the Jenkins VMware Lab Manager Slaves Plugin that stems from a missing permission check in the form validation method. This flaw allows attackers with Overall/Read permissions to initiate connections to arbitrary servers, potentially compromising the integrity and security of the Jenkins environment.
Affected Version(s)
Jenkins VMware Lab Manager Slaves Plugin all versions as of 2019-04-03