CVE-2019-16541: Exposure of Resource to Wrong Sphere
(updated )
Jenkins JIRA does not declare the correct (folder) scope for per-folder Jira site definitions, allowing users to select and use credentials with System scope.
References
Detect and mitigate CVE-2019-16541 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →