First published: Thu Nov 21 2019(Updated: )
Jenkins JIRA Plugin 3.0.10 and earlier does not declare the correct (folder) scope for per-folder Jira site definitions, allowing users to select and use credentials with System scope.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/jenkins-jira-plugin | <3.0.11 | 3.0.11 |
redhat/jenkins | <2-plugins-0:3.11.1597310986-1.el7 | 2-plugins-0:3.11.1597310986-1.el7 |
redhat/jenkins | <2-plugins-0:4.6.1601368321-1.el8 | 2-plugins-0:4.6.1601368321-1.el8 |
Jenkins Jira | <=3.0.10 | |
maven/org.jenkins-ci.plugins:jira | <=3.0.10 | 3.0.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-16541 is a vulnerability in the Jenkins JIRA Plugin that allows users to select and use credentials with System scope.
The severity of CVE-2019-16541 is critical with a severity value of 9.9.
CVE-2019-16541 affects Jenkins through the JIRA Plugin version 3.0.10 and earlier.
To fix CVE-2019-16541, update the Jenkins JIRA Plugin to version 3.0.11 or later.
More information about CVE-2019-16541 can be found at the following references: https://www.cve.org/CVERecord?id=CVE-2019-16541 https://nvd.nist.gov/vuln/detail/CVE-2019-16541 https://jenkins.io/security/advisory/2019-11-21/#SECURITY-1106 https://bugzilla.redhat.com/show_bug.cgi?id=1819663 https://access.redhat.com/errata/RHSA-2020:3541