Missing Permission Check in Jenkins Pipeline Shared Groovy Libraries Plugin
CVE-2019-10357
4.3MEDIUM
Key Information:
- Vendor
- Jenkins
- Vendor
- CVE Published:
- 31 July 2019
Summary
A missing permission check vulnerability in the Jenkins Pipeline: Shared Groovy Libraries Plugin versions 2.14 and earlier permits users with Overall/Read access to retrieve limited information regarding the content of source code management (SCM) repositories referenced through global libraries. This oversight could potentially expose sensitive information to unauthorized users, emphasizing the importance of strict access controls and proper validation measures in systems relying on shared libraries.
Affected Version(s)
Jenkins Pipeline: Shared Groovy Libraries Plugin 2.14 and earlier
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved