cbcvebase.
CVE-2019-10305
published 2019-04-18

CVE-2019-10305: A missing permission check in Jenkins XebiaLabs XL Deploy Plugin in the Credential#doValidateUserNamePassword form validation method allows attackers with…

medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
A missing permission check in Jenkins XebiaLabs XL Deploy Plugin in the Credential#doValidateUserNamePassword form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.

Affected

6 ranges
VendorProductVersion rangeFixed in
jenkinsazure_publishersettings_credentials_plugin
jenkinsgitlab_plugin
jenkinsthis_allowed_users_able_to_control_the_plugin
jenkinsxebialabs_xl_deploy<= 7.5.3
jenkinsxebialabs_xl_deploy_plugin
jenkins_projectjenkins_xebialabs_xl_deploy_plugin