Description
A missing permission check in Jenkins XPath Configuration Viewer Plugin 1.1.1 and earlier allows attackers with Overall/Read permission to create and delete XPath expressions.
Remediation
References
https://www.jenkins.io/security/advisory/2022-06-30/#SECURITY-2658
Related Vulnerabilities
CVE-2020-15842 Vulnerability in maven package com.liferay:com.liferay.portal.template.freemarker
CVE-2020-2242 Vulnerability in maven package org.jenkins-ci.plugins:database
CVE-2021-30638 Vulnerability in maven package org.apache.tapestry:tapestry-core
CVE-2014-0003 Vulnerability in maven package org.apache.camel:camel-core
CVE-2015-2912 Vulnerability in maven package com.orientechnologies:orientdb-core