CVE-2019-10308

Source
https://nvd.nist.gov/vuln/detail/CVE-2019-10308
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-10308.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-10308
Aliases
Published
2019-04-30T13:29:05Z
Modified
2024-09-03T02:22:05.847681Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

A missing permission check in Jenkins Static Analysis Utilities Plugin 1.95 and earlier in the DefaultGraphConfigurationView#doSave form handler method allowed attackers with Overall/Read permission to change the per-job default graph configuration for all users.

References

Affected packages

Git / github.com/jenkinsci/analysis-core-plugin

Affected ranges

Type
GIT
Repo
https://github.com/jenkinsci/analysis-core-plugin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

analysis-core-1.*

analysis-core-1.17
analysis-core-1.18
analysis-core-1.19
analysis-core-1.20
analysis-core-1.21
analysis-core-1.22
analysis-core-1.23
analysis-core-1.24
analysis-core-1.25
analysis-core-1.26
analysis-core-1.27
analysis-core-1.28
analysis-core-1.29
analysis-core-1.30
analysis-core-1.31
analysis-core-1.32
analysis-core-1.33
analysis-core-1.34
analysis-core-1.35
analysis-core-1.36
analysis-core-1.37
analysis-core-1.38
analysis-core-1.39
analysis-core-1.40
analysis-core-1.41
analysis-core-1.42
analysis-core-1.43
analysis-core-1.44
analysis-core-1.45
analysis-core-1.46
analysis-core-1.47
analysis-core-1.48
analysis-core-1.49
analysis-core-1.50
analysis-core-1.51
analysis-core-1.52
analysis-core-1.53
analysis-core-1.54
analysis-core-1.55
analysis-core-1.56
analysis-core-1.57
analysis-core-1.58
analysis-core-1.59
analysis-core-1.60
analysis-core-1.61
analysis-core-1.62
analysis-core-1.63
analysis-core-1.64
analysis-core-1.65
analysis-core-1.66
analysis-core-1.67
analysis-core-1.68
analysis-core-1.69
analysis-core-1.70
analysis-core-1.71
analysis-core-1.72
analysis-core-1.73
analysis-core-1.74
analysis-core-1.75
analysis-core-1.76
analysis-core-1.77
analysis-core-1.78
analysis-core-1.79
analysis-core-1.80
analysis-core-1.81
analysis-core-1.82
analysis-core-1.83
analysis-core-1.84
analysis-core-1.86
analysis-core-1.87
analysis-core-1.88
analysis-core-1.89
analysis-core-1.90
analysis-core-1.91
analysis-core-1.92
analysis-core-1.93
analysis-core-1.94
analysis-core-1.95