CVE-2019-10308 | xxxCVE-2019-10308 – xxx
菜单

CVE-2019-10308

九月 30, 2020 - 未分类

  1. CVE-Search
  2. CVE-2019-10308
ID CVE-2019-10308
SummaryA missing permission check in Jenkins Static Analysis Utilities Plugin 1.95 and earlier in the DefaultGraphConfigurationView#doSave form handler method allowed attackers with Overall/Read permission to change the per-job default graph configuration for all users.
References
Vulnerable Configurations
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.0:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.0:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.1:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.1:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.2:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.2:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.3:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.3:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.4:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.4:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.5:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.5:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.6:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.6:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.7:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.7:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.8:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.8:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.9:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.9:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.10:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.10:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.11:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.11:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.12:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.12:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.13:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.13:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.14:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.14:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.15:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.15:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.16:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.16:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.17:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.17:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.18:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.18:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.19:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.19:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.20:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.20:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.21:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.21:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.22:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.22:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.23:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.23:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.24:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.24:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.25:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.25:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.26:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.26:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.27:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.27:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.28:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.28:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.29:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.29:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.30:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.30:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.31:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.31:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.32:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.32:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.33:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.33:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.34:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.34:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.35:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.35:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.36:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.36:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.37:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.37:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.38:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.38:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.39:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.39:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.40:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.40:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.41:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.41:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.42:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.42:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.43:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.43:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.44:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.44:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.45:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.45:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.46:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.46:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.47:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.47:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.48:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.48:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.49:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.49:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.50:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.50:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.51:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.51:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.52:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.52:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.53:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.53:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.54:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.54:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.55:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.55:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.56:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.56:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.57:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.57:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.58:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.58:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.59:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.59:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.60:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.60:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.61:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.61:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.62:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.62:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.63:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.63:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.64:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.64:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.65:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.65:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.66:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.66:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.67:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.67:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.68:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.68:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.69:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.69:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.70:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.70:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.71:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.71:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.72:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.72:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.73:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.73:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.74:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.74:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.75:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.75:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.76:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.76:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.77:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.77:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.78:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.78:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.79:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.79:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.80:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.80:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.81:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.81:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.82:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.82:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.83:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.83:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.84:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.84:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.85:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.85:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.86:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.86:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.87:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.87:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.88:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.88:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.89:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.89:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.90:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.90:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.91:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.91:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.92:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.92:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.93:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.93:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.94:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.94:*:*:*:*:jenkins:*:*
  • cpe:2.3:a:jenkins:static_analysis_utilities:1.95:*:*:*:*:jenkins:*:*
    cpe:2.3:a:jenkins:static_analysis_utilities:1.95:*:*:*:*:jenkins:*:*
CVSS
Base: 4.0 (as of 02-10-2020 – 14:42)
Impact:
Exploitability:
CWECWE-862
CAPEC

    Access
    VectorComplexityAuthentication
    NETWORKLOWSINGLE
    Impact
    ConfidentialityIntegrityAvailability
    NONEPARTIALNONE
    cvss-vector via4 AV:N/AC:L/Au:S/C:N/I:P/A:N
    refmap via4
    bid 108159
    confirm https://jenkins.io/security/advisory/2019-04-30/#SECURITY-1100
    mlist [oss-security] 20190430 Multiple vulnerabilities in Jenkins plugins
    Last major update02-10-2020 – 14:42
    Published30-04-2019 – 13:29
    Last modified02-10-2020 – 14:42

    Notice: Undefined variable: canUpdate in /var/www/html/wordpress/wp-content/plugins/wp-autopost-pro/wp-autopost-function.php on line 51