CVE-2019-1003035: Medium severity jenkins azure vm agents vulnerability
An information exposure vulnerability exists in Jenkins Azure VM Agents Plugin 0.8.0 and earlier in src/main/java/com/microsoft/azure/vmagent/AzureVMAgentTemplate.java, src/main/java/com/microsoft/azure/vmagent/AzureVMCloud.java that allows attackers with Overall/Read permission to perform the 'verify configuration' form validation action, thereby obtaining limited information about the Azure configuration.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1003035?
CVE-2019-1003035 has been classified as a medium severity vulnerability due to the potential for information exposure.
How do I fix CVE-2019-1003035?
To fix CVE-2019-1003035, update the Jenkins Azure VM Agents Plugin to version 0.8.1 or later.
What versions are affected by CVE-2019-1003035?
CVE-2019-1003035 affects Jenkins Azure VM Agents Plugin versions 0.8.0 and earlier.
Who can exploit CVE-2019-1003035?
CVE-2019-1003035 can be exploited by attackers with Overall/Read permission on the affected Jenkins instance.
What kind of vulnerability is CVE-2019-1003035?
CVE-2019-1003035 is an information exposure vulnerability that allows unauthorized access to sensitive information.