Required CVE Record Information
Description
A missing permission check in Jenkins Test Results Aggregator Plugin 1.2.13 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.
References 2 Total
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 2 Total
- jenkins.io: Jenkins Security Advisory 2023-07-12 vendor-advisoryx_transferred
- http://www.openwall.com/lists/oss-security/2023/07/12/2 x_transferred