Description
A missing permission check in Jenkins DotCi Plugin 2.40.00 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository for attacker-specified commits.
Remediation
References
https://www.jenkins.io/security/advisory/2022-09-21/#SECURITY-2867
Related Vulnerabilities
CVE-2022-25167 Vulnerability in maven package org.apache.flume.flume-ng-sources:flume-jms-source
CVE-2022-23621 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore
CVE-2023-49373 Vulnerability in maven package com.jfinal:jfinal
CVE-2023-45135 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web-war