#VU23671 Improper access control in Build Failure Analyzer - CVE-2019-16554
Published: December 18, 2019
Build Failure Analyzer
Jenkins
Description
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the affected plugin does not perform a permission check in a method performing form validation. A remote authenticated user with Overall/Read access can have Jenkins evaluate a computationally expensive regular expression.