CVE-2019-1003083: Medium severity jenkins vulnerability
A missing permission check in Jenkins Gearman Plugin in the GearmanPluginConfig#doTestConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1003083?
CVE-2019-1003083 is classified as a medium severity vulnerability due to its potential for exploitation by users with minimal permissions.
How do I fix CVE-2019-1003083?
To fix CVE-2019-1003083, update the Jenkins Gearman Plugin to version 0.4.0 or later.
What does CVE-2019-1003083 allow attackers to do?
CVE-2019-1003083 allows attackers with Overall/Read permission to initiate connections to an attacker-specified server.
Which versions of the Jenkins Gearman Plugin are affected by CVE-2019-1003083?
Versions of the Jenkins Gearman Plugin prior to 0.4.0 are affected by CVE-2019-1003083.
Is the issue in CVE-2019-1003083 related to form validation?
Yes, the issue in CVE-2019-1003083 is related to a missing permission check in the form validation method.