VYPR
High severityNVD Advisory· Published Dec 17, 2019· Updated Aug 5, 2024

CVE-2019-16566

CVE-2019-16566

Description

Jenkins Team Concert Plugin lacks a permission check, enabling attackers with Overall/Read to connect to an attacker-controlled URL and capture stored credentials.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Jenkins Team Concert Plugin lacks a permission check, enabling attackers with Overall/Read to connect to an attacker-controlled URL and capture stored credentials.

Vulnerability

Description CVE-2019-16566 is a missing permission check in the Jenkins Team Concert Plugin versions 1.3.0 and earlier. The plugin fails to validate whether a user has the required permissions to perform certain actions that involve connecting to an external URL using attacker-specified credential IDs. This allows attackers with at least Overall/Read permission to exploit the issue, provided they have obtained a valid credential ID through another vulnerability or method [1][4].

Exploitation

An attacker can craft a request to a form validation endpoint or similar functionality that does not enforce proper authorization. By supplying a malicious URL and a known credential ID, the plugin will initiate a connection to the specified server, sending the stored credentials in the process. The attack does not require full administrative access, only Overall/Read, which is a relatively low privilege level in Jenkins [3].

Impact

Successful exploitation allows an attacker to capture credentials stored in Jenkins, such as passwords, tokens, or other secrets. This can lead to further compromise of Jenkins-integrated systems and services, as the stolen credentials may provide elevated access [4].

Mitigation

Status As of the advisory publication date (2019-12-17), no fix was available for the Team Concert Plugin. The plugin is listed among those with unresolved security issues, and users are advised to restrict access to Jenkins or disable the plugin if possible [1][3].

AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.jenkins-ci.plugins:teamconcertMaven
<= 1.3.0

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.