File Upload Vulnerability in Jenkins ElectricFlow Plugin by CloudBees
CVE-2019-10334
6.5MEDIUM
Summary
The Jenkins ElectricFlow Plugin prior to version 1.1.6 contains a critical security flaw that disables SSL/TLS and hostname verification globally for the Jenkins master JVM during file uploads using MultipartUtility.java. This vulnerability exposes sensitive data to potential interception by attackers, compromising the integrity and confidentiality of the uploaded files. It is essential for users of affected versions to upgrade to ensure robust security measures are in place.
Affected Version(s)
Jenkins ElectricFlow Plugin 1.1.5 and earlier
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved