CVE-2019-10377: Medium severity jenkins vulnerability
Published Aug 7, 2019
·Updated
A missing permission check in Jenkins Avatar Plugin 1.2 and earlier allows attackers with Overall/Read access to change the avatar of any user of Jenkins.
Affected Software
2 affected components
maven/net.hurstfrost.jenkins:avatar<1.2
Jenkins Avatar Jenkins<=1.2
Event History
Aug 7, 2019
CVE Published
via MITRE·02:20 PM
Data Sourced
via MITRE·02:20 PM
Description
May 24, 2022
Advisory Published
via GitHub·04:52 PM
Frequently Asked Questions
1
What is the severity of CVE-2019-10377?
CVE-2019-10377 is rated as a medium severity vulnerability.
2
How do I fix CVE-2019-10377?
To fix CVE-2019-10377, upgrade the Jenkins Avatar Plugin to version 1.3 or later.
3
Who is affected by CVE-2019-10377?
CVE-2019-10377 affects all Jenkins installations using the Avatar Plugin version 1.2 or earlier.
4
What does CVE-2019-10377 allow attackers to do?
CVE-2019-10377 allows attackers with Overall/Read access to change the avatar of any Jenkins user.
5
Is there a patch available for CVE-2019-10377?
Yes, a patch is available in the updated version of the Jenkins Avatar Plugin.