Improper Authorization in Jenkins Configuration Plugin by CloudBees
CVE-2019-10344
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 31 July 2019
What is CVE-2019-10344?
The Jenkins Configuration as Code Plugin prior to version 1.24 contains a flaw where missing permission checks on critical HTTP endpoints allow users with Overall/Read access to obtain sensitive information. This unauthorized access enables these users to view the generated schema and documentation pertaining to the plugin, potentially exposing insights about other installed plugins and configurations. The oversight raises significant security implications for environments utilizing Jenkins.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jenkins Configuration as Code Plugin 1.24 and earlier
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved