CVE-2019-10357: Medium severity jenkins pipeline vulnerability

Published Jul 31, 2019
·
Updated

A missing permission check in Jenkins Pipeline: Shared Groovy Libraries Plugin 2.14 and earlier allowed users with Overall/Read access to obtain limited information about the content of SCM repositories referenced by global libraries.

Other sources

The Jenkins Pipeline: Shared Groovy Libraries Plugin provides form validation to determine whether the revision (e.g. commit, tag, or branch name) specified for a global library exists in the repository. This form validation method lacked a permission check, allowing attackers with Overall/Read access to determine whether an attacker-specified revision exists in an SCM repository configured for use in an existing shared library.

Pipeline: Shared Groovy Libraries Plugin now performs the appropriate permission check.

External References:

https://jenkins.io/security/advisory/2019-07-31/#SECURITY-1422

Red Hat

Affected Software

5 affected componentsFixes available
maven/org.jenkins-ci.plugins.workflow:workflow-cps-global-lib<=2.14
2.15
redhat/jenkins-plugin-workflow-cps-global-lib<2.15
2.15
Jenkins Pipeline\<=2.14
redhat OpenShift Container Platform=3.11
redhat OpenShift Container Platform=4.1

Event History

Jul 31, 2019
CVE Published
via MITRE·12:45 PM
Data Sourced
via MITRE·12:45 PM
Description
May 24, 2022
Advisory Published
04:51 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2019-10357?

CVE-2019-10357 has a medium severity rating due to a missing permission check that could allow unauthorized access to SCM repository information.

2

How do I fix CVE-2019-10357?

To fix CVE-2019-10357, upgrade the Jenkins Pipeline: Shared Groovy Libraries Plugin to version 2.15 or later.

3

What systems are affected by CVE-2019-10357?

CVE-2019-10357 affects Jenkins Pipeline: Shared Groovy Libraries Plugin version 2.14 and earlier, as well as certain versions of Red Hat OpenShift Container Platform.

4

What type of vulnerability is CVE-2019-10357?

CVE-2019-10357 is a permissions-related vulnerability that allows users to access limited information in SCM repositories.

5

Can I mitigate CVE-2019-10357 without upgrading?

Mitigation options are limited; the recommended action is to upgrade the affected plugin to avoid risk.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203