Lucene search

K
osvGoogleOSV:GHSA-FHGG-J92H-29RC
HistoryMay 13, 2022 - 1:25 a.m.

Missing permission check in Jenkins SOASTA CloudTest Plugin

2022-05-1301:25:16
Google
osv.dev
10
jenkins
soasta cloudtest
permission check
form validation
attackers
connection
server
security vulnerability

AI Score

6.5

Confidence

High

EPSS

0.001

Percentile

44.8%

A missing permission check in Jenkins SOASTA CloudTest Plugin in the CloudTestServer.DescriptorImpl#doValidate form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.

AI Score

6.5

Confidence

High

EPSS

0.001

Percentile

44.8%

Related for OSV:GHSA-FHGG-J92H-29RC