Missing Permission Check in Jenkins Docker Plugin Allows Unauthorized Access
CVE-2019-10341
6.5MEDIUM
What is CVE-2019-10341?
A vulnerability in the Jenkins Docker Plugin allows users with Overall/Read access to connect to a specified URL using attacker-provided credentials. This omission in permission checks can lead to the exposure of sensitive stored credentials within Jenkins. By exploiting this weakness, attackers can gain unauthorized access to Jenkins environments, compromising the integrity and confidentiality of the system. Users are advised to review their plugin versions and ensure they update to patched releases to mitigate this risk.
Affected Version(s)
Jenkins Docker Plugin 1.1.6 and earlier