CVE-2019-10301

Severity
8.8HIGH
EPSS
0.1%
top 79.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 18
Latest updateMay 24

Description

A missing permission check in Jenkins GitLab Plugin 1.5.11 and earlier in the GitLabConnectionConfig#doTestConnection form validation method allowed attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

CVEListV5jenkins_project/jenkins_gitlab_plugin1.5.11 and earlier
NVDjenkins/gitlab1.5.11

🔴Vulnerability Details

3
GHSA
Jenkins GitLab Plugin missing permission checks2022-05-24
OSV
Jenkins GitLab Plugin missing permission checks2022-05-24
CVEList
CVE-2019-10301: A missing permission check in Jenkins GitLab Plugin 12019-04-18

📋Vendor Advisories

2
GitLab
CVE-2019-10301: A missing permission check in Jenkins GitLab Plugin 1.5.11 and earlier in the GitLabConnectionConfig#doTestConnection form validation method allowed a2019-04-18
Jenkins
Jenkins Security Advisory 2019-04-172019-04-17