{"id":"GHSA-98m4-m2c3-qxgq","summary":"Jenkins JIRA Plugin allows users to select and use credentials with System scope","details":"Jenkins JIRA Plugin 3.0.10 and earlier does not declare the correct (folder) scope for per-folder Jira site definitions, allowing users to select and use credentials with System scope. Jira Plugin 3.0.11 defines the appropriate folder context for credential lookup. As a side effect, existing per-folder Jira sites may lose access to already configured System-scoped credentials, as if no credential was specified in the first place.","aliases":["CVE-2019-16541"],"modified":"2024-01-02T05:51:56.991082Z","published":"2022-05-24T17:01:40Z","database_specific":{"nvd_published_at":"2019-11-21T15:15:00Z","cwe_ids":["CWE-668"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-12-06T21:56:30Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-16541"},{"type":"WEB","url":"https://github.com/jenkinsci/jira-plugin/commit/3214a54b6871d82cb34a26949aad93b0fa78d1a8"},{"type":"PACKAGE","url":"https://github.com/jenkinsci/jira-plugin"},{"type":"WEB","url":"https://jenkins.io/security/advisory/2019-11-21/#SECURITY-1106"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2019/11/21/1"}],"affected":[{"package":{"name":"org.jenkins-ci.plugins:jira","ecosystem":"Maven","purl":"pkg:maven/org.jenkins-ci.plugins/jira"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.11"}]}],"versions":["1.27","1.28","1.29","1.30","1.31","1.32","1.33","1.34","1.35","1.36","1.37","1.38","1.39","1.41","2.0","2.0.2","2.0.3","2.1","2.2","2.2.1","2.3","2.3.1","2.4","2.4.2","2.5","2.5.1","2.5.2","3.0.0","3.0.1","3.0.10","3.0.2","3.0.3","3.0.4","3.0.5","3.0.6","3.0.6.1","3.0.7","3.0.8","3.0.9"],"database_specific":{"last_known_affected_version_range":"\u003c= 3.0.10","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-98m4-m2c3-qxgq/GHSA-98m4-m2c3-qxgq.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}