CVE-2019-1003047
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 1.5%
exploitation probability
1.5%top 27% of all CVEs
observed exploitation
nono source reports it
A missing permission check in Jenkins Fortify on Demand Uploader Plugin 3.0.10 and earlier allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.
Affected products
Jenkins project · Jenkins Fortify on Demand Uploader Plugin