High severity7.5NVD Advisory· Published May 31, 2019· Updated Jun 17, 2026
CVE-2019-10330
CVE-2019-10330
Description
Jenkins Gitea Plugin 1.1.1 and earlier did not implement trusted revisions, allowing attackers without commit access to the Git repo to change Jenkinsfiles even if Jenkins is configured to consider them to be untrusted.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins:giteaMaven | < 1.1.2 | 1.1.2 |
Affected products
3- Range: 1.1.1 and earlier
Patches
Vulnerability mechanics
References
6- www.openwall.com/lists/oss-security/2019/05/31/2nvdMailing ListThird Party AdvisoryWEB
- www.securityfocus.com/bid/108540nvdThird Party AdvisoryVDB EntryWEB
- github.com/advisories/GHSA-q98c-rqx7-7ghfghsaADVISORY
- jenkins.io/security/advisory/2019-05-31/nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2019-10330ghsaADVISORY
- github.com/jenkinsci/gitea-plugin/commit/7555cb7c168cfa49d31271e7d65d76c1fab311f7ghsaWEB
News mentions
0No linked articles in our index yet.