ASA-2019-00614 – Jenkins Global Post Script Plugin: Missing permission check

Jenkins Global Post Script Plugin does not perform permission checks on a method implementing form validation. This allows users with Overall/Read permission to list the files contained in $JENKINS_HOME/global-post-script that can be used by the plugin.

ASA-2019-00612 – Jenkins Libvirt Slaves Plugin: Missing permission checks

Jenkins Libvirt Slaves Plugin does not perform permission checks on a method implementing form validation. This allows users with Overall/Read access to Jenkins to connect to an attacker-specified SSH server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

ASA-2019-00609 – Jenkins ElasticBox Kubernetes CI/CD Plugin: Missing permission checks

Jenkins ElasticBox Kubernetes CI/CD Plugin does not perform permission checks on a method implementing form validation. This allows users with Overall/Read access to Jenkins to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

ASA-2019-00605 – Jenkins Deploy WebLogic Plugin: Missing permission check

Deploy WebLogic Plugin does not perform permission checks on a method implementing form validation. This allows users with Overall/Read access to Jenkins to send an HTTP HEAD request to a user-specified URL, or confirm the existence of any file or directory on the Jenkins master.

ASA-2019-00603 – Jenkins Dynatrace Application Monitoring Plugin: Missing permission check

Dynatrace Application Monitoring Plugin does not perform permission checks on a method implementing form validation. This allows users with Overall/Read access to Jenkins to initiate a connection test to an attacker-specified server with attacker specified username and password. As of publication of this advisory, there is no fix.