Input validation error in Configuration as Code - CVE-2019-10362

 

Input validation error in Configuration as Code - CVE-2019-10362

Published: October 4, 2019


Vulnerability identifier: #VU21536
CSH Severity: Medium
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-10362
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input when processing YAML files. A remote authenticated attacker with permission to change Jenkins system configuration can specify crafted descriptions containing variable references and obtain the values of environment variables.


Affected software

Configuration as Code

How to mitigate CVE-2019-10362

Install updates from vendor's website.

Configuration as Code - update to 1.25

External References

Related Security Bulletins