Description
Jenkins Gitea Plugin 1.1.1 and earlier did not implement trusted revisions, allowing attackers without commit access to the Git repo to change Jenkinsfiles even if Jenkins is configured to consider them to be untrusted.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/05/31/2
http://www.securityfocus.com/bid/108540
https://jenkins.io/security/advisory/2019-05-31/#SECURITY-1046
Related Vulnerabilities
CVE-2019-10242 Vulnerability in maven package org.eclipse.kura:org.eclipse.kura.web2
CVE-2021-23358 Vulnerability in npm package underscore
CVE-2019-10306 Vulnerability in maven package org.jenkins-ci.plugins:ontrack
CVE-2021-30246 Vulnerability in npm package jsrsasign
CVE-2019-12397 Vulnerability in maven package org.apache.ranger:ranger