CVE-2019-10439: Medium severity jenkins crx content package deployer vulnerability
A missing permission check in Jenkins CRX Content Package Deployer Plugin 1.8.1 and earlier in various 'doFillCredentialsIdItems' methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.
Other sources
A missing permission check in Jenkins CRX Content Package Deployer Plugin prior to version 1.9 in various 'doFillCredentialsIdItems' methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins. This issue is patched in version 1.9.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10439?
CVE-2019-10439 has a medium severity rating due to the potential for unauthorized credential enumeration.
How do I fix CVE-2019-10439?
To fix CVE-2019-10439, upgrade the Jenkins CRX Content Package Deployer Plugin to version 1.9 or later.
Who is affected by CVE-2019-10439?
CVE-2019-10439 affects users of Jenkins CRX Content Package Deployer Plugin versions 1.8.1 and earlier.
What causes CVE-2019-10439?
CVE-2019-10439 is caused by a missing permission check in the 'doFillCredentialsIdItems' methods allowing unauthorized access to credentials.
Can CVE-2019-10439 lead to data breaches?
Yes, CVE-2019-10439 can potentially lead to data breaches by allowing unauthorized users to enumerate sensitive credentials.