CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 4.3. It affects Jenkins.
CVE
CVE-2019-10344
Severity
MEDIUM
CVSS
4.3
EPSS
0.69%
Jenkins
Original NVD Description
Missing permission checks in Jenkins Configuration as Code Plugin 1.24 and earlier in various HTTP endpoints allowed users with Overall/Read access to access the generated schema and documentation for this plugin containing detailed information about installed plugins.
Related CVEs
Other vulnerabilities affecting the same vendor(s)