Description
A missing check in Jenkins TestQuality Updater Plugin 1.3 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified username and password.
Remediation
References
https://www.jenkins.io/security/advisory/2023-01-24/#SECURITY-2800
Related Vulnerabilities
CVE-2023-34034 Vulnerability in maven package org.springframework.security:spring-security-config
CVE-2013-1966 Vulnerability in maven package com.opensymphony:xwork-core
CVE-2020-9489 Vulnerability in maven package org.apache.tika:tika-parsers
CVE-2018-1000086 Vulnerability in npm package pym.js
CVE-2010-5312 Vulnerability in maven package org.fujion.webjars:jquery-ui