CVE-2019-1003076 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Jenkins Audit to Database Plugin. This flaw allows an unauthenticated attacker to trick a legitimate user into initiating a connection to an attacker-specified JDBC server through the DbAuditPublisherDescriptorImpl#doTestJdbcConnection form validation method. Rated Medium severity (CVSS 6.5), it requires user interaction (UI:R) but can lead to high integrity impact (I:H) by potentially exposing sensitive connection details or facilitating further attacks. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:jenkins:audit_to_database:*:*:*:*:*:jenkins:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.