CVE-2019-16541: Critical severity jenkins vulnerability
Jenkins JIRA Plugin 3.0.10 and earlier does not declare the correct (folder) scope for per-folder Jira site definitions, allowing users to select and use credentials with System scope.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2019-16541?
CVE-2019-16541 is a vulnerability in the Jenkins JIRA Plugin that allows users to select and use credentials with System scope.
What is the severity of CVE-2019-16541?
The severity of CVE-2019-16541 is critical with a severity value of 9.9.
How does CVE-2019-16541 affect Jenkins?
CVE-2019-16541 affects Jenkins through the JIRA Plugin version 3.0.10 and earlier.
How do I fix CVE-2019-16541?
To fix CVE-2019-16541, update the Jenkins JIRA Plugin to version 3.0.11 or later.
Where can I find more information about CVE-2019-16541?
More information about CVE-2019-16541 can be found at the following references: https://www.cve.org/CVERecord?id=CVE-2019-16541 https://nvd.nist.gov/vuln/detail/CVE-2019-16541 https://jenkins.io/security/advisory/2019-11-21/#SECURITY-1106 https://bugzilla.redhat.com/show_bug.cgi?id=1819663 https://access.redhat.com/errata/RHSA-2020:3541