Jenkins Gitea Plugin 1.1.1 and earlier did not implement trusted revisions, allowing attackers without commit access to the Git repo to change Jenkinsfiles even if Jenkins is configured to consider them to be untrusted.
References
Link | Resource |
---|---|
http://www.openwall.com/lists/oss-security/2019/05/31/2 | Mailing List Third Party Advisory |
http://www.securityfocus.com/bid/108540 | Third Party Advisory VDB Entry |
https://jenkins.io/security/advisory/2019-05-31/#SECURITY-1046 | Vendor Advisory |
http://www.openwall.com/lists/oss-security/2019/05/31/2 | Mailing List Third Party Advisory |
http://www.securityfocus.com/bid/108540 | Third Party Advisory VDB Entry |
https://jenkins.io/security/advisory/2019-05-31/#SECURITY-1046 | Vendor Advisory |
Configurations
History
21 Nov 2024, 04:18
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.openwall.com/lists/oss-security/2019/05/31/2 - Mailing List, Third Party Advisory | |
References | () http://www.securityfocus.com/bid/108540 - Third Party Advisory, VDB Entry | |
References | () https://jenkins.io/security/advisory/2019-05-31/#SECURITY-1046 - Vendor Advisory |
Information
Published : 2019-05-31 15:29
Updated : 2024-11-21 04:18
NVD link : CVE-2019-10330
Mitre link : CVE-2019-10330
CVE.ORG link : CVE-2019-10330
JSON object : View
Products Affected
gitea
- gitea
CWE
CWE-862
Missing Authorization