Permissions, Privileges, and Access Controls in JClouds - CVE-2019-10369
Published: October 4, 2019 / Updated: October 4, 2019
JClouds
Detailed vulnerability description
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to missing permission check in "BlobStoreProfile.DescriptorImpl#doTestConnection" and "JCloudsCloud.DescriptorImpl#doTestConnection". A remote authenticated attacker can capture credentials stored in Jenkins.