A missing permission check in... CVE-2022-25208

6.5 AV AC AU C I A
发布: 2022-02-15
修订: 2024-11-21

A missing permission check in Jenkins Chef Sinatra Plugin 1.20 and earlier allows attackers with Overall/Read permission to have Jenkins send an HTTP request to an attacker-controlled URL and have it parse an XML response.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息