Description
A missing check in Jenkins dbCharts Plugin 0.5.2 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified database via JDBC using attacker-specified credentials.
Remediation
References
https://www.jenkins.io/security/advisory/2022-02-15/#SECURITY-2177
Related Vulnerabilities
CVE-2013-2165 Vulnerability in maven package org.richfaces.framework:richfaces-impl
CVE-2023-31098 Vulnerability in maven package org.apache.inlong:manager-pojo
CVE-2023-36478 Vulnerability in maven package org.eclipse.jetty.http3:http3-qpack
CVE-2023-28326 Vulnerability in maven package org.apache.openmeetings:openmeetings-parent