Description
A missing permission check in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 and earlier allows attackers with Overall/Read permissions to connect to an attacker-specified webserver using attacker-specified credentials.
Remediation
References
https://www.jenkins.io/security/advisory/2022-09-21/#SECURITY-2737
Related Vulnerabilities
CVE-2020-2228 Vulnerability in maven package org.jenkins-ci.plugins:gitlab-oauth
CVE-2023-46731 Vulnerability in maven package org.xwiki.platform:xwiki-platform-administration-ui
CVE-2019-12421 Vulnerability in maven package org.apache.nifi:nifi-web
CVE-2012-0394 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2016-8744 Vulnerability in maven package org.apache.brooklyn:brooklyn