Allele Security Alert
ASA-2019-00609
Identifier(s)
ASA-2019-00609, CVE-2019-10469, SECURITY-1005 (1)
Title
Missing permission checks
Vendor(s)
Gustavo Llorente
Guillermo Sanchez Urien
Product(s)
Jenkins ElasticBox Kubernetes CI/CD Plugin
Affected version(s)
Jenkins ElasticBox Kubernetes CI/CD Plugin versions up to and including 1.3
Fixed version(s)
Unknown
Proof of concept
Unknown
Description
Jenkins ElasticBox Kubernetes CI/CD Plugin does not perform permission checks on a method implementing form validation. This allows users with Overall/Read access to Jenkins to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Technical details
Unknown
Credits
Oleg Nenashev (CloudBees, Inc)
Reference(s)
Jenkins Security Advisory 2019-10-23
https://jenkins.io/security/advisory/2019-10-23/#SECURITY-1005 (1)
Jenkins security advisory
https://groups.google.com/d/msg/jenkinsci-advisories/KCv6eDsiV3Y/GNr0aDC3AQAJ
oss-security – Multiple vulnerabilities in Jenkins plugins
https://www.openwall.com/lists/oss-security/2019/10/23/2
Jenkins Plugins
https://plugins.jenkins.io/kubernetes-ci
CVE-2019-10469
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10469
CVE-2019-10469
https://nvd.nist.gov/vuln/detail/CVE-2019-10469
If there is any error in this alert or you wish a comprehensive analysis, let us know.
Last modified: December 3, 2019