Missing Permission Check in Jenkins Reviewbot Plugin Enables Unauthorized Server Connections
CVE-2019-10279
6.5MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 4 April 2019
What is CVE-2019-10279?
A security vulnerability exists in the Jenkins Reviewbot Plugin that stems from a missing permission check within the 'doTestConnection' method. This flaw allows users with Overall/Read permission to connect to a server specified by an attacker. Such unauthorized access may lead to significant security risks if exploited, as it could allow attackers to communicate with any external server, potentially exposing sensitive data or compromising the system integrity.
Affected Version(s)
Jenkins jenkins-reviewbot Plugin all versions as of 2019-04-03