CVE-2019-16567: Medium severity ibm rational team concert vulnerability
A missing permission check in Jenkins Team Concert Plugin 1.3.0 and earlier in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-16567?
CVE-2019-16567 is classified as a medium severity vulnerability due to its potential impact on credential enumeration.
How do I fix CVE-2019-16567?
To address CVE-2019-16567, upgrade the Jenkins Team Concert Plugin to version 1.3.1 or later where the permission check has been added.
What are the specific affected versions in CVE-2019-16567?
CVE-2019-16567 affects Jenkins Team Concert Plugin versions 1.3.0 and earlier.
What type of vulnerability is CVE-2019-16567?
CVE-2019-16567 is a missing permission check vulnerability that allows users to enumerate stored credentials.
Who is at risk from CVE-2019-16567?
Users with Overall/Read access in Jenkins are at risk from CVE-2019-16567 as they can exploit this vulnerability.