CVE-2019-16554: Medium severity jenkins build failure analyzer plugin vulnerability
A missing permission check in Jenkins Build Failure Analyzer Plugin 1.24.1 and earlier allows attackers with Overall/Read permission to have Jenkins evaluate a computationally expensive regular expression.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-16554?
CVE-2019-16554 is a vulnerability in the Jenkins Build Failure Analyzer Plugin that allows attackers with Overall/Read permission to have Jenkins evaluate a computationally expensive regular expression.
What is the severity of CVE-2019-16554?
The severity of CVE-2019-16554 is medium (4.3).
How does CVE-2019-16554 affect Jenkins Build Failure Analyzer Plugin?
CVE-2019-16554 affects Jenkins Build Failure Analyzer Plugin 1.24.1 and earlier versions.
How can I fix CVE-2019-16554?
To fix CVE-2019-16554, users should update to version 1.24.2 of the Jenkins Build Failure Analyzer Plugin.
Where can I find more information about CVE-2019-16554?
More information about CVE-2019-16554 can be found at the following references: [http://www.openwall.com/lists/oss-security/2019/12/17/1](http://www.openwall.com/lists/oss-security/2019/12/17/1), [https://jenkins.io/security/advisory/2019-12-17/#SECURITY-1651](https://jenkins.io/security/advisory/2019-12-17/#SECURITY-1651), [https://nvd.nist.gov/vuln/detail/CVE-2019-16554](https://nvd.nist.gov/vuln/detail/CVE-2019-16554)