CVE-2019-10330: High severity gitea vulnerability
Jenkins Gitea Plugin 1.1.1 and earlier did not implement trusted revisions, allowing attackers without commit access to the Git repo to change Jenkinsfiles even if Jenkins is configured to consider them to be untrusted.
Other sources
Jenkins Gitea Plugin prior to 1.1.2 did not implement trusted revisions, allowing attackers without commit access to the Git repo to change Jenkinsfiles even if Jenkins is configured to consider them to be untrusted.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-10330?
CVE-2019-10330 is a vulnerability in Jenkins Gitea Plugin 1.1.1 and earlier that allows attackers without commit access to the Git repo to change Jenkinsfiles.
How does CVE-2019-10330 affect Gitea?
CVE-2019-10330 affects Gitea versions up to and including 1.1.1.
What is the severity of CVE-2019-10330?
CVE-2019-10330 has a severity rating of 7.5 (high).
How can an attacker exploit CVE-2019-10330?
An attacker without commit access to the Git repo can exploit CVE-2019-10330 by changing Jenkinsfiles.
Is there a fix for CVE-2019-10330?
Yes, updating Jenkins Gitea Plugin to a version higher than 1.1.1 fixes CVE-2019-10330.