Description
A missing permission check in Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified hostname and port using attacker-specified username and password.
Remediation
References
https://www.jenkins.io/security/advisory/2023-11-29/#SECURITY-3256
http://www.openwall.com/lists/oss-security/2023/11/29/1
Related Vulnerabilities
CVE-2022-43766 Vulnerability in maven package org.apache.iotdb:tsfile
CVE-2021-22132 Vulnerability in maven package org.elasticsearch:elasticsearch
CVE-2022-36883 Vulnerability in maven package org.jenkins-ci.plugins:git
CVE-2022-28154 Vulnerability in maven package org.jenkins-ci.plugins:covcomplplot
CVE-2022-31692 Vulnerability in maven package org.springframework.security:spring-security-web