Allele Security Alert
ASA-2019-00605
Identifier(s)
ASA-2019-00605, CVE-2019-10465, SECURITY-820
Title
Missing permission check
Vendor(s)
Raphael CHAUMIER
Product(s)
Jenkins Deploy WebLogic Plugin
Affected version(s)
Jenkins Deploy WebLogic Plugin up to and including 4.1
Fixed version(s)
Unknown
Proof of concept
Unknown
Description
Deploy WebLogic Plugin does not perform permission checks on a method implementing form validation. This allows users with Overall/Read access to Jenkins to send an HTTP HEAD request to a user-specified URL, or confirm the existence of any file or directory on the Jenkins master.
Technical details
Unknown
Credits
Thomas de Grenier de Latour
Reference(s)
Jenkins Security Advisory 2019-10-23
https://jenkins.io/security/advisory/2019-10-23/#SECURITY-820
Jenkins security advisory
https://groups.google.com/d/msg/jenkinsci-advisories/KCv6eDsiV3Y/GNr0aDC3AQAJ
oss-security – Multiple vulnerabilities in Jenkins plugins
https://www.openwall.com/lists/oss-security/2019/10/23/2
Jenkins Plugins
https://plugins.jenkins.io/weblogic-deployer-plugin
CVE-2019-10465
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10465
CVE-2019-10465
https://nvd.nist.gov/vuln/detail/CVE-2019-10465
If there is any error in this alert or you wish a comprehensive analysis, let us know.
Last modified: November 4, 2019