Missing Permission Check in Jenkins SOASTA CloudTest Plugin
CVE-2019-1003091
6.5MEDIUM
Summary
A flaw exists in the Jenkins SOASTA CloudTest Plugin, where a missing permission check in the CloudTestServer.DescriptorImpl#doValidate method permits users with Overall/Read permissions to establish connections to predetermined servers. This vulnerability could potentially allow unauthorized actions by attackers, leading to security breaches.
Affected Version(s)
Jenkins SOASTA CloudTest Plugin all versions as of 2019-04-03
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved