Description
A missing permission check in Jenkins Active Directory Plugin 2.19 and earlier allows attackers with Overall/Read permission to access the domain health check diagnostic page.
Remediation
References
https://www.jenkins.io/security/advisory/2020-11-04/#SECURITY-1999
Related Vulnerabilities
CVE-2022-40705 Vulnerability in maven package soap:soap
CVE-2016-3086 Vulnerability in maven package org.apache.hadoop:hadoop-common
CVE-2022-24280 Vulnerability in maven package org.apache.pulsar:pulsar-proxy
CVE-2019-10398 Vulnerability in maven package org.jenkins-ci.plugins:beaker-builder
CVE-2011-5064 Vulnerability in maven package org.apache.tomcat:catalina