cbcvebase.
CVE-2019-10290
published 2019-04-04

CVE-2019-10290: A missing permission check in Jenkins Netsparker Cloud Scan Plugin 1.1.5 and older in the NCScanBuilder.DescriptorImpl#doValidateAPI form validation method…

PriorityP335medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
EPSS
1.54%
71.9th percentile
A missing permission check in Jenkins Netsparker Cloud Scan Plugin 1.1.5 and older in the NCScanBuilder.DescriptorImpl#doValidateAPI form validation method allowed attackers with Overall/Read permission to initiate a connection to an attacker-specified server.

Affected

47 ranges· showing 25
VendorProductVersion rangeFixed in
jenkinsamazon_sns_build_notifier_plugin
jenkinsaqua_security_scanner_plugin
jenkinsassembla_auth_plugin
jenkinsaudit_to_database_plugin
jenkinsaws_cloudwatch_logs_publisher_plugin
jenkinsaws_elastic_beanstalk_publisher_plugin
jenkinsbitbucket_approve_plugin
jenkinsbugzilla_plugin
jenkinscloudcoreo_deploytime_plugin
jenkinscloudformation_plugin
jenkinscloudshare_docker-machine_plugin
jenkinscrowd_integration_plugin
jenkinsdeployhub_plugin
jenkinsdiawi_upload_plugin
jenkinsftp_publisher_plugin
jenkinsgearman_plugin
jenkinshockeyapp_plugin
jenkinshyper.sh_commons_plugin
jenkinsirc_plugin
jenkinsjabber_server_plugin
jenkinsjira_issue_updater_plugin
jenkinsklaros-testmanagement_plugin
jenkinskoji_plugin
jenkinsminio_storage_plugin
jenkinsnetsparker_cloud_scan<= 1.1.5

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.