Description
An incorrect permission check in Jenkins requests-plugin Plugin 2.2.16 and earlier allows attackers with Overall/Read permission to view the list of pending requests.
Remediation
References
https://www.jenkins.io/security/advisory/2022-06-30/#SECURITY-2650
Related Vulnerabilities
CVE-2023-44487 Vulnerability in maven package org.eclipse.jetty.http2:http2-common
CVE-2016-0711 Vulnerability in maven package org.apache.portals.jetspeed-2:j2-admin
CVE-2023-33201 Vulnerability in maven package org.bouncycastle:bcprov-jdk14
CVE-2023-36665 Vulnerability in maven package org.webjars.npm:github-com-protobufjs-protobuf-js
CVE-2020-16040 Vulnerability in maven package org.webjars.npm:electron