Description
A missing permission check in Jenkins Code Dx Plugin 3.1.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL.
Remediation
References
https://www.jenkins.io/security/advisory/2023-05-16/#SECURITY-3118
Related Vulnerabilities
CVE-2020-13959 Vulnerability in maven package org.apache.velocity.tools:velocity-tools-view
CVE-2023-28640 Vulnerability in maven package io.apiman:apiman-manager-api-rest-impl
CVE-2019-10425 Vulnerability in maven package org.jvnet.hudson.plugins:gcal
CVE-2019-16568 Vulnerability in maven package hudson.plugins.sctmexecutor:sctmexecutor
CVE-2015-8857 Vulnerability in maven package org.webjars.npm:uglify-js