Description
A missing permission check in Jenkins DotCi Plugin 2.40.00 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository for attacker-specified commits.
Remediation
References
https://www.jenkins.io/security/advisory/2022-09-21/#SECURITY-2867
Related Vulnerabilities
CVE-2023-46233 Vulnerability in maven package org.webjars.npm:github-com-brix-crypto-js
CVE-2011-1772 Vulnerability in maven package com.opensymphony:xwork-core
CVE-2019-10354 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2013-2067 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2018-6341 Vulnerability in maven package org.webjars.bower:vue