CVE Published: 04/04/2019 |
CVE Updated: 05/08/2024 |
CVE Year: 2019 Source: jenkins |
Vendor: Jenkins project |
Product: Jenkins Zephyr Enterprise Test Management Plugin Status : PUBLISHED
CVE-2019-1003085 Description
A missing permission check in Jenkins Zephyr Enterprise Test Management Plugin in the ZeeDescriptor#doTestConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.