CVE-2019-16541 – org.jenkins-ci.plugins:jira
Package
Manager: maven
Name: org.jenkins-ci.plugins:jira
Vulnerable Version: >=0 <3.0.11
Severity
Level: Medium
CVSS v3.1: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00475 pctl0.6385
Details
Jenkins JIRA Plugin allows users to select and use credentials with System scope Jenkins JIRA Plugin 3.0.10 and earlier does not declare the correct (folder) scope for per-folder Jira site definitions, allowing users to select and use credentials with System scope. Jira Plugin 3.0.11 defines the appropriate folder context for credential lookup. As a side effect, existing per-folder Jira sites may lose access to already configured System-scoped credentials, as if no credential was specified in the first place.
Metadata
Created: 2022-05-24T17:01:40Z
Modified: 2022-12-06T21:56:30Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-98m4-m2c3-qxgq/GHSA-98m4-m2c3-qxgq.json
CWE IDs: ["CWE-668"]
Alternative ID: GHSA-98m4-m2c3-qxgq
Finding: F017
Auto approve: 1