Description
A missing permission check in Jenkins Active Directory Plugin 2.19 and earlier allows attackers with Overall/Read permission to access the domain health check diagnostic page.
Remediation
References
https://www.jenkins.io/security/advisory/2020-11-04/#SECURITY-1999
Related Vulnerabilities
CVE-2022-24728 Vulnerability in npm package ckeditor4
CVE-2021-22160 Vulnerability in maven package org.apache.pulsar:pulsar-broker-common
CVE-2023-29205 Vulnerability in maven package org.xwiki.platform:xwiki-platform-rendering-xwiki
CVE-2018-1261 Vulnerability in maven package org.springframework.integration:spring-integration-zip
CVE-2019-10445 Vulnerability in maven package org.jenkins-ci.plugins:google-kubernetes-engine