Description
A missing permission check in Jenkins Jianliao Notification Plugin 1.1 and earlier allows attackers with Overall/Read permission to send HTTP POST requests to an attacker-specified URL.
Remediation
References
https://www.jenkins.io/security/advisory/2022-06-22/#SECURITY-2240
Related Vulnerabilities
CVE-2016-6814 Vulnerability in maven package org.codehaus.groovy:groovy-all
CVE-2016-2175 Vulnerability in maven package org.apache.pdfbox:jempbox
CVE-2019-16561 Vulnerability in maven package org.jenkins-ci.plugins:websphere-deployer
CVE-2019-1003078 Vulnerability in maven package org.jenkins-ci.plugins:labmanager
CVE-2021-37942 Vulnerability in maven package co.elastic.apm:elastic-apm-agent