CVE-2019-10436 | xxxCVE-2019-10436 – xxx
菜单

CVE-2019-10436

九月 30, 2020 - 未分类

  1. CVE-Search
  2. CVE-2019-10436
ID CVE-2019-10436
SummaryAn arbitrary file read vulnerability in Jenkins Google OAuth Credentials Plugin 0.9 and earlier allowed attackers able to configure jobs and credentials in Jenkins to obtain the contents of any file on the Jenkins master.
References
Vulnerable Configurations
  • cpe:2.3:a:jenkins:google_oauth_credentials:0.1:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:google_oauth_credentials:0.1:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:google_oauth_credentials:0.2:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:google_oauth_credentials:0.2:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:google_oauth_credentials:0.3:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:google_oauth_credentials:0.3:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:google_oauth_credentials:0.4:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:google_oauth_credentials:0.4:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:google_oauth_credentials:0.5:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:google_oauth_credentials:0.5:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:google_oauth_credentials:0.6:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:google_oauth_credentials:0.6:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:google_oauth_credentials:0.7:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:google_oauth_credentials:0.7:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:google_oauth_credentials:0.8:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:google_oauth_credentials:0.8:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:google_oauth_credentials:0.9:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:google_oauth_credentials:0.9:*:*:*:*:jenkins:*:*
CVSS
Base: 4.0 (as of 01-10-2020 – 16:45)
Impact:
Exploitability:
CWENVD-CWE-Other
CAPEC

    Access
    VectorComplexityAuthentication
    NETWORKLOWSINGLE
    Impact
    ConfidentialityIntegrityAvailability
    PARTIALNONENONE
    cvss-vector via4 AV:N/AC:L/Au:S/C:P/I:N/A:N
    refmap via4
    confirm https://jenkins.io/security/advisory/2019-10-16/#SECURITY-1583
    mlist [oss-security] 20191016 Multiple vulnerabilities in Jenkins plugins
    Last major update01-10-2020 – 16:45
    Published16-10-2019 – 14:15
    Last modified01-10-2020 – 16:45

    Notice: Undefined variable: canUpdate in /var/www/html/wordpress/wp-content/plugins/wp-autopost-pro/wp-autopost-function.php on line 51