CVE-2019-16566: CSRF
A missing permission check in Jenkins Team Concert Plugin 1.3.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Other sources
Jenkins Team Concert Plugin 1.3.0 and earlier does not perform permission checks on a method implementing form validation. This allows users with Overall/Read access to Jenkins to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Additionally, the form validation method does not require POST requests, resulting in a CSRF vulnerability.
As of publication of this advisory, there is no fix.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-16566?
CVE-2019-16566 has a medium severity rating due to the risk of credential exposure.
How do I fix CVE-2019-16566?
To fix CVE-2019-16566, update the Jenkins Team Concert Plugin to version 1.3.1 or later.
Who is affected by CVE-2019-16566?
Users of Jenkins Team Concert Plugin version 1.3.0 and earlier are affected by CVE-2019-16566.
What types of attacks are possible with CVE-2019-16566?
CVE-2019-16566 allows attackers with Overall/Read permission to connect to a specified URL and capture credentials.
When was CVE-2019-16566 disclosed?
CVE-2019-16566 was disclosed on December 17, 2019.