CVE-2019-10333: Medium severity jenkins electricflow vulnerability
Missing permission checks in Jenkins ElectricFlow Plugin 1.1.5 and earlier in various HTTP endpoints allowed users with Overall/Read access to obtain information about the Jenkins ElectricFlow Plugin configuration and configuration of connected ElectricFlow instances.
Other sources
Various form validation and form autocompletion methods in CloudBees CD Plugin lacked permission checks. This allowed attackers with Overall/Read access to obtain information about the configuration of CloudBees CD Plugin, as well as the configuration and data of connected ElectricFlow servers.
These form validation and autocompletion methods now require Overall/Administer or Job/Configure permission, as appropriate for the given method.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10333?
The severity of CVE-2019-10333 is medium with a CVSS score of 4.3.
What is the affected software for CVE-2019-10333?
The affected software for CVE-2019-10333 is Jenkins ElectricFlow Plugin version 1.1.5 and earlier.
How does CVE-2019-10333 affect CloudBees CD Plugin?
CVE-2019-10333 allows attackers with Overall/Read access to obtain information about the configuration of CloudBees CD Plugin, as well as the configuration and data of connected ElectricFlow servers.
Are there any references for CVE-2019-10333?
Yes, the references for CVE-2019-10333 are: http://www.openwall.com/lists/oss-security/2019/06/11/1, http://www.securityfocus.com/bid/108747, and https://jenkins.io/security/advisory/2019-06-11/#SECURITY-1410%20(2).
What is the Common Weakness Enumeration (CWE) ID for CVE-2019-10333?
The Common Weakness Enumeration (CWE) ID for CVE-2019-10333 is CWE-862 and CWE-285.