CVE Published: 04/04/2019 |
CVE Updated: 05/08/2024 |
CVE Year: 2019 Source: jenkins |
Vendor: Jenkins project |
Product: Jenkins Audit to Database Plugin Status : PUBLISHED
CVE-2019-1003077 Description
A missing permission check in Jenkins Audit to Database Plugin in the DbAuditPublisherDescriptorImpl#doTestJdbcConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.