Missing Permission Check in Jenkins Zephyr Enterprise Test Management Plugin
CVE-2019-1003085

6.5MEDIUM

Key Information:

Vendor
Jenkins
Vendor
CVE Published:
4 April 2019

Summary

A vulnerability involves a missing permission check in the Jenkins Zephyr Enterprise Test Management Plugin specifically within the ZeeDescriptor#doTestConnection form validation method. This flaw permits attackers who possess Overall/Read permission to create connections to servers specified by an attacker, potentially leading to unauthorized access and manipulation of system data. Correcting this vulnerability hinges on implementing robust permission checks to ensure that only authorized users can initiate server connections.

Affected Version(s)

Jenkins Zephyr Enterprise Test Management Plugin all versions as of 2019-04-03

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.