Description
A missing permission check in Jenkins Rundeck Plugin allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.
Remediation
References
https://jenkins.io/security/advisory/2019-10-16/#SECURITY-1460
Related Vulnerabilities
CVE-2020-2168 Vulnerability in maven package org.jenkins-ci.plugins:azure-acs
CVE-2022-2256 Vulnerability in maven package org.keycloak:keycloak-themes
CVE-2020-13949 Vulnerability in maven package org.apache.thrift:libthrift
CVE-2022-34806 Vulnerability in maven package org.jenkins-ci.plugins:jigomerge
CVE-2023-25500 Vulnerability in maven package com.vaadin:vaadin