Description
A missing permission check in Jenkins Code Dx Plugin 3.1.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL.
Remediation
References
https://www.jenkins.io/security/advisory/2023-05-16/#SECURITY-3118
Related Vulnerabilities
CVE-2022-36896 Vulnerability in maven package com.compuware.jenkins:compuware-scm-downloader
CVE-2023-33962 Vulnerability in maven package io.jstach:jstachio
CVE-2020-11971 Vulnerability in maven package org.apache.camel:camel-spring
CVE-2023-27898 Vulnerability in maven package org.jenkins-ci.main:jenkins-core