CVE-2019-1003079: Medium severity jenkins vmware lab manager slaves vulnerability
A missing permission check in Jenkins VMware Lab Manager Slaves Plugin in the LabManager.DescriptorImpl#doTestConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2019-1003079.
What is the title of this vulnerability?
The title of this vulnerability is 'A missing permission check in Jenkins VMware Lab Manager Slaves Plugin in the LabManager.DescriptorImpl#doTestConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.'
What is the severity of CVE-2019-1003079?
The severity of CVE-2019-1003079 is medium with a CVSS score of 6.5.
What software is affected by CVE-2019-1003079?
Jenkins VMware Lab Manager Slaves Plugin version 0.2.8 is affected by CVE-2019-1003079.
How can an attacker exploit CVE-2019-1003079?
An attacker with Overall/Read permission can initiate a connection to an attacker-specified server.