Missing Permission Check in Jenkins Alauda DevOps Pipeline Plugin
CVE-2019-16574
6.5MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 17 December 2019
What is CVE-2019-16574?
A security issue in the Alauda DevOps Pipeline Plugin for Jenkins allows attackers with Overall/Read permissions to connect to arbitrary URLs, leveraging attacker-specified credential IDs. This exposes sensitive credentials saved within Jenkins, potentially leading to unauthorized access and compromise of confidential data.
Affected Version(s)
Jenkins Alauda DevOps Pipeline Plugin <= 2.3.2