« Volver al listado

CVE-2019-10333

Estado: ModificadaMedia (4.3)—

Missing permission checks in Jenkins ElectricFlow Plugin 1.1.5 and earlier in various HTTP endpoints allowed users with Overall/Read access to obtain information about the Jenkins ElectricFlow Plugin configuration and configuration of connected ElectricFlow instances.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-10333",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "jenkinsci-cert@googlegroups.com",
      "affectedData": [
        {
          "vendor": "Jenkins project",
          "product": "Jenkins ElectricFlow Plugin",
          "versions": [
            {
              "status": "affected",
              "version": "1.1.5 and earlier"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-06-11T14:29:00.900",
  "references": [
    {
      "url": "http://www.openwall.com/lists/oss-security/2019/06/11/1",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "jenkinsci-cert@googlegroups.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/108747",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "jenkinsci-cert@googlegroups.com"
    },
    {
      "url": "https://jenkins.io/security/advisory/2019-06-11/#SECURITY-1410%20%282%29",
      "source": "jenkinsci-cert@googlegroups.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2019/06/11/1",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/108747",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://jenkins.io/security/advisory/2019-06-11/#SECURITY-1410%20%282%29",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-862"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Missing permission checks in Jenkins ElectricFlow Plugin 1.1.5 and earlier in various HTTP endpoints allowed users with Overall/Read access to obtain information about the Jenkins ElectricFlow Plugin configuration and configuration of connected ElectricFlow instances."
    },
    {
      "lang": "es",
      "value": "Una  falta de comprobación de permisos en el Plugin ElectricFlow de Jenkins versión 1.1.5 y anteriores, en varios endpoints HTTP permitieron a los usuarios con acceso General y de Lectura obtener información sobre la configuración del Plugin ElectricFlow de Jenkins y la configuración de las instancias de ElectricFlow conectadas."
    }
  ],
  "lastModified": "2026-06-17T02:10:44.113",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:jenkins:electricflow:*:*:*:*:*:jenkins:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FC1DBB7B-0A05-4FA8-9CB2-775193ECC96E",
              "versionEndIncluding": "1.1.5"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "jenkinsci-cert@googlegroups.com"
}