CVE-2019-16567
published 2019-12-17CVE-2019-16567: A missing permission check in Jenkins Team Concert Plugin 1.3.0 and earlier in form-related methods allowed users with Overall/Read access to enumerate…
medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
A missing permission check in Jenkins Team Concert Plugin 1.3.0 and earlier in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | alauda_devops_pipeline_plugin | — | — |
| jenkins | alauda_kubernetes_suport_plugin | — | — |
| jenkins | build_failure_analyzer_plugin | — | — |
| jenkins | gerrit_trigger_plugin | — | — |
| jenkins | ids_in_team_concert_plugin | — | — |
| jenkins | ids_to_allow_users_configuring_the_plugin | — | — |
| jenkins | jenkins_and_plugin | — | — |
| jenkins | mantis_plugin | — | — |
| jenkins | maven_release_plug-in_plugin | — | — |
| jenkins | mission_control_plugin | — | — |
| jenkins | pipeline_aggregator_view_plugin | — | — |
| jenkins | rapiddeploy_plugin | — | — |
| jenkins | redgate_sql_change_automation_plugin | — | — |
| jenkins | rundeck_plugin | — | — |
| jenkins | sctmexecutor_plugin | — | — |
| jenkins | spira_importer_plugin | — | — |
| jenkins | team_concert | <= 1.3.0 | — |
| jenkins | team_concert_plugin | — | — |
| jenkins | websphere_deployer_plugin | — | — |
| jenkins | weibo_plugin | — | — |
| jenkins_project | jenkins_team_concert_plugin | unspecified – 1.3.0 | — |