Description
A missing permission check in Jenkins EasyQA Plugin 1.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified HTTP server.
Remediation
References
https://www.jenkins.io/security/advisory/2022-06-22/#SECURITY-2281
Related Vulnerabilities
CVE-2023-5763 Vulnerability in maven package org.glassfish.main.orb:orb-connector
CVE-2022-43434 Vulnerability in maven package io.jenkins.plugins:neuvector-vulnerability-scanner
CVE-2019-1003036 Vulnerability in maven package org.jenkins-ci.plugins:azure-vm-agents
CVE-2019-1003051 Vulnerability in maven package org.jvnet.hudson.plugins:ircbot