Permission Check Flaw in Jenkins RapidDeploy Plugin Affects User Security
CVE-2019-16571
4.3MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 17 December 2019
What is CVE-2019-16571?
The Jenkins RapidDeploy Plugin version 4.1 and earlier contains a flaw due to a missing permission check. This vulnerability allows users with Overall/Read permission to establish connections to any specified web server, potentially exposing sensitive data and leading to unauthorized actions on the server. It is crucial for users to audit their Jenkins configurations and apply the necessary updates to mitigate this risk.
Affected Version(s)
Jenkins RapidDeploy Plugin <= 4.1