« Volver al listado

CVE-2019-1003043

Estado: ModificadaAlta (7.5)—

A missing permission check in Jenkins Slack Notification Plugin 2.19 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-1003043",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 3.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:S/C:P/I:N/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.6
      }
    ]
  },
  "affected": [
    {
      "source": "jenkinsci-cert@googlegroups.com",
      "affectedData": [
        {
          "vendor": "Jenkins project",
          "product": "Jenkins Slack Notification Plugin",
          "versions": [
            {
              "status": "affected",
              "version": "2.19 and earlier"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-03-28T18:29:00.390",
  "references": [
    {
      "url": "http://www.openwall.com/lists/oss-security/2019/03/28/2",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "jenkinsci-cert@googlegroups.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/107628",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "jenkinsci-cert@googlegroups.com"
    },
    {
      "url": "https://jenkins.io/security/advisory/2019-03-25/#SECURITY-976",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "jenkinsci-cert@googlegroups.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2019/03/28/2",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/107628",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://jenkins.io/security/advisory/2019-03-25/#SECURITY-976",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-862"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A missing permission check in Jenkins Slack Notification Plugin 2.19 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de comprobación de permiso en el plugin \"Jenkins Slack Notification\", en versiones 2.19 y anteriores, permite a los atacantes con acceso \"Overall/Read\" conectarse a la URL especificada por el atacante usando los identificadores de credenciales especificadas por el atacante que se obtienen a través de otro método, capturando las credenciales almacenadas en Jenkins."
    }
  ],
  "lastModified": "2026-06-17T02:09:36.120",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:jenkins:slack_notification:*:*:*:*:*:jenkins:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1B27FA86-F2EE-45FF-9BDA-692916F5FC53",
              "versionEndIncluding": "2.19"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "jenkinsci-cert@googlegroups.com"
}