Description
A missing permission check in Jenkins Rundeck Plugin allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.
Remediation
References
https://jenkins.io/security/advisory/2019-10-16/#SECURITY-1460
Related Vulnerabilities
CVE-2020-1945 Vulnerability in maven package org.apache.ant:ant
CVE-2022-42126 Vulnerability in maven package com.liferay:com.liferay.depot.service
CVE-2021-36163 Vulnerability in maven package org.apache.dubbo:dubbo-serialization
CVE-2021-22569 Vulnerability in maven package com.google.protobuf:protobuf-java
CVE-2014-0119 Vulnerability in maven package org.apache.tomcat:tomcat-jasper