Description
A missing permission check in Jenkins vRealize Orchestrator Plugin 3.0 and earlier allows attackers with Overall/Read permission to send an HTTP POST request to an attacker-specified URL.
Remediation
References
https://www.jenkins.io/security/advisory/2022-06-22/#SECURITY-2279
Related Vulnerabilities
CVE-2015-0899 Vulnerability in maven package struts:struts
CVE-2019-1003073 Vulnerability in maven package org.jenkins-ci.plugins:vsts-cd
CVE-2020-2193 Vulnerability in maven package io.jenkins.plugins:echarts-api
CVE-2022-34197 Vulnerability in maven package org.jenkins-ci.plugins:sauce-ondemand
CVE-2021-20334 Vulnerability in npm package mongodb-js-metrics