CVE-2019-10305
18.04.2019, 17:29
A missing permission check in Jenkins XebiaLabs XL Deploy Plugin in the Credential#doValidateUserNamePassword form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.Enginsight
Vendor | Product | Version |
---|---|---|
jenkins | xebialabs_xl_deploy | 𝑥 ≤ 7.5.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration