A missing permission check in... CVE-2019-10439

4.0 AV AC AU C I A
发布: 2019-10-16
修订: 2023-10-25

A missing permission check in Jenkins CRX Content Package Deployer Plugin 1.8.1 and earlier in various 'doFillCredentialsIdItems' methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息