Description
A missing permission check in Jenkins RapidDeploy Plugin 4.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified web server.
Remediation
References
https://jenkins.io/security/advisory/2019-12-17/#SECURITY-1604
http://www.openwall.com/lists/oss-security/2019/12/17/1
Related Vulnerabilities
CVE-2019-1003051 Vulnerability in maven package org.jvnet.hudson.plugins:ircbot
CVE-2016-5016 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-common
CVE-2023-29201 Vulnerability in maven package org.xwiki.commons:xwiki-commons-xml
CVE-2023-31062 Vulnerability in maven package org.apache.inlong:manager-service
CVE-2017-15697 Vulnerability in maven package org.apache.nifi:nifi-jetty