Missing Permission Check in Jenkins Pipeline Shared Groovy Libraries Plugin
CVE-2019-10357
4.3MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 31 July 2019
What is CVE-2019-10357?
A missing permission check vulnerability in the Jenkins Pipeline: Shared Groovy Libraries Plugin versions 2.14 and earlier permits users with Overall/Read access to retrieve limited information regarding the content of source code management (SCM) repositories referenced through global libraries. This oversight could potentially expose sensitive information to unauthorized users, emphasizing the importance of strict access controls and proper validation measures in systems relying on shared libraries.
Affected Version(s)
Jenkins Pipeline: Shared Groovy Libraries Plugin 2.14 and earlier