CVE-2019-10333

Severity
4.3MEDIUM
EPSS
0.0%
top 87.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11
Latest updateMay 24

Description

Missing permission checks in Jenkins ElectricFlow Plugin 1.1.5 and earlier in various HTTP endpoints allowed users with Overall/Read access to obtain information about the Jenkins ElectricFlow Plugin configuration and configuration of connected ElectricFlow instances.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages3 packages

🔴Vulnerability Details

3
GHSA
Jenkins ElectricFlow Plugin Missing permission checks2022-05-24
OSV
Jenkins ElectricFlow Plugin Missing permission checks2022-05-24
CVEList
CVE-2019-10333: Missing permission checks in Jenkins ElectricFlow Plugin 12019-06-11

📋Vendor Advisories

1
Jenkins
Jenkins Security Advisory 2019-06-112019-06-11