Description
A missing permission check in Jenkins database Plugin 1.6 and earlier allows attackers with Overall/Read access to Jenkins to connect to an attacker-specified database server using attacker-specified credentials.
Remediation
References
https://jenkins.io/security/advisory/2020-09-01/#SECURITY-1024
http://www.openwall.com/lists/oss-security/2020/09/01/3
Related Vulnerabilities
CVE-2022-25937 Vulnerability in npm package glance
CVE-2021-22096 Vulnerability in maven package org.springframework:spring-core
CVE-2018-1190 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-model
CVE-2020-1929 Vulnerability in maven package org.apache.beam:beam-sdks-java-io-mongodb
CVE-2022-23496 Vulnerability in maven package nl.basjes.parse.useragent:yauaa-elasticsearch-8