Description
A missing permission check in Jenkins Rundeck Plugin allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.
Remediation
References
https://jenkins.io/security/advisory/2019-10-16/#SECURITY-1460
Related Vulnerabilities
CVE-2016-10364 Vulnerability in npm package kibana
CVE-2018-1199 Vulnerability in maven package org.springframework.security:spring-security-web
CVE-2019-1003069 Vulnerability in maven package org.jenkins-ci.plugins:aqua-security-scanner
CVE-2020-27216 Vulnerability in maven package org.mortbay.jetty:jetty
CVE-2023-39685 Vulnerability in maven package org.hjson:hjson