Information Exposure Affecting org.jenkins-ci.plugins:jira package, versions [,3.0.11)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.09% (42nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGJENKINSCIPLUGINS-535485
  • published24 Nov 2019
  • disclosed21 Nov 2019
  • creditDaniel Beck, CloudBees, Inc.

Introduced: 21 Nov 2019

CVE-2019-16541  (opens in a new tab)
CWE-668  (opens in a new tab)

How to fix?

Upgrade org.jenkins-ci.plugins:jira to version 3.0.11 or higher.

Overview

org.jenkins-ci.plugins:jira is a Jenkins plugin that has an optional feature to update JIRA issues with a back pointer to Jenkins build pages. This allows the submitter and watchers to quickly find out which build they need to pick up to get the fix.

Affected versions of this package are vulnerable to Information Exposure. It does not declare the correct (folder) scope for per-folder Jira site definitions, allowing users to select and use credentials with System scope.

CVSS Scores

version 3.1