Allele Security Alert
ASA-2019-00612
Identifier(s)
ASA-2019-00612, CVE-2019-10472, SECURITY-1014 (1)
Title
Missing permission checks
Vendor(s)
Philipp Bartsch
Marco Mornati
Nigel Magnay
Product(s)
Jenkins Libvirt Slaves Plugin
Affected version(s)
Jenkins Libvirt Slaves Plugin versions up to and including 1.8.5
Fixed version(s)
Unknown
Proof of concept
Unknown
Description
Jenkins Libvirt Slaves Plugin does not perform permission checks on a method implementing form validation. This allows users with Overall/Read access to Jenkins to connect to an attacker-specified SSH server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Technical details
Unknown
Credits
Oleg Nenashev (CloudBees, Inc)
Reference(s)
Jenkins Security Advisory 2019-10-23
https://jenkins.io/security/advisory/2019-10-23/#SECURITY-1014 (1)
Jenkins security advisory
https://groups.google.com/d/msg/jenkinsci-advisories/KCv6eDsiV3Y/GNr0aDC3AQAJ
oss-security – Multiple vulnerabilities in Jenkins plugins
https://www.openwall.com/lists/oss-security/2019/10/23/2
Jenkins Plugins
https://plugins.jenkins.io/libvirt-slave
CVE-2019-10472
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10472
CVE-2019-10472
https://nvd.nist.gov/vuln/detail/CVE-2019-10472
If there is any error in this alert or you wish a comprehensive analysis, let us know.
Last modified: December 5, 2019