Description
A missing check in Jenkins TestQuality Updater Plugin 1.3 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified username and password.
Remediation
References
https://www.jenkins.io/security/advisory/2023-01-24/#SECURITY-2800
Related Vulnerabilities
CVE-2023-28640 Vulnerability in maven package io.apiman:apiman-manager-api-rest-impl
CVE-2019-16563 Vulnerability in maven package tech.andrey.jenkins:mission-control-view
CVE-2021-31408 Vulnerability in maven package com.vaadin:flow-client
CVE-2021-42340 Vulnerability in maven package org.apache.tomcat:tomcat-websocket
CVE-2023-33946 Vulnerability in maven package com.liferay.portal:release.portal.bom