Lucene search

K
cveJenkinsCVE-2019-1003044
HistoryMar 28, 2019 - 6:29 p.m.

CVE-2019-1003044

2019-03-2818:29:00
CWE-352
jenkins
web.nvd.nist.gov
30
cve-2019-1003044
cross-site request forgery
csrf
jenkins slack notification plugin
nvd
security vulnerability

CVSS2

2.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:S/C:P/I:N/A:N

CVSS3

7.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

EPSS

0.003

Percentile

66.7%

A cross-site request forgery vulnerability in Jenkins Slack Notification Plugin 2.19 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

Affected configurations

Nvd
Node
jenkinsslack_notificationRange2.19jenkins
VendorProductVersionCPE
jenkinsslack_notification*cpe:2.3:a:jenkins:slack_notification:*:*:*:*:*:jenkins:*:*

CNA Affected

[
  {
    "product": "Jenkins Slack Notification Plugin",
    "vendor": "Jenkins project",
    "versions": [
      {
        "status": "affected",
        "version": "2.19 and earlier"
      }
    ]
  }
]

CVSS2

2.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:S/C:P/I:N/A:N

CVSS3

7.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

EPSS

0.003

Percentile

66.7%

Related for CVE-2019-1003044