CVE-2019-10312

Publication date

2019-04-30 12:25:17

Family

jenkins

State

PUBLISHED

Description

A missing permission check in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.TowerInstallationDescriptor#doFillTowerCredentialsIdItems method allowed attackers with Overall/Read permission to enumerate credentials ID of credentials stored in Jenkins.