Description
A missing permission check in Jenkins Jianliao Notification Plugin 1.1 and earlier allows attackers with Overall/Read permission to send HTTP POST requests to an attacker-specified URL.
Remediation
References
https://www.jenkins.io/security/advisory/2022-06-22/#SECURITY-2240
Related Vulnerabilities
CVE-2020-6532 Vulnerability in npm package electron
CVE-2023-22602 Vulnerability in maven package org.apache.shiro:shiro-spring-boot-starter
CVE-2017-2604 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2023-48219 Vulnerability in maven package org.webjars:tinymce
CVE-2019-10434 Vulnerability in maven package com.mtvi.plateng.hudson:ldapemail