#VU23693 Improper access control in Team Concert - CVE-2019-16566
Published: December 19, 2019
Team Concert
Jenkins
Description
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the affected software does not perform permission checks on a method implementing form validation. A remote user with Overall/Read access can connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.