Missing Permission Check in Jenkins Pipeline Shared Groovy Libraries Plugin
CVE-2019-10357

4.3MEDIUM

Key Information:

Vendor
Jenkins
Vendor
CVE Published:
31 July 2019

Summary

A missing permission check vulnerability in the Jenkins Pipeline: Shared Groovy Libraries Plugin versions 2.14 and earlier permits users with Overall/Read access to retrieve limited information regarding the content of source code management (SCM) repositories referenced through global libraries. This oversight could potentially expose sensitive information to unauthorized users, emphasizing the importance of strict access controls and proper validation measures in systems relying on shared libraries.

Affected Version(s)

Jenkins Pipeline: Shared Groovy Libraries Plugin 2.14 and earlier

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.