Description
A data modification vulnerability exists in Jenkins Agiletestware Pangolin Connector for TestRail Plugin 2.1 and earlier in GlobalConfig.java that allows attackers with Overall/Read permission to override this plugin's configuration by sending crafted HTTP requests to an unprotected endpoint.
Remediation
References
https://jenkins.io/security/advisory/2018-07-30/#SECURITY-995
Related Vulnerabilities
CVE-2022-24697 Vulnerability in maven package org.apache.kylin:kylin-spark-engine
CVE-2020-28469 Vulnerability in npm package glob-parent
CVE-2016-10642 Vulnerability in npm package cmake
CVE-2018-3738 Vulnerability in npm package protobufjs
CVE-2020-27543 Vulnerability in npm package restify-paginate