Lucene search

K
osvGoogleOSV:GHSA-GRMG-5Q49-MQMF
HistoryMay 14, 2022 - 1:38 a.m.

Jenkins Crowd 2 Integration Plugin server-side request forgery vulnerability

2022-05-1401:38:17
Google
osv.dev
7
jenkins
integration
plugin
server-side
forgery
vulnerability
authorization
crowdsecurityrealm
connection
test
credentials
settings

AI Score

6.6

Confidence

High

EPSS

0.001

Percentile

21.9%

An improper authorization vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in CrowdSecurityRealm.java that allows attackers to have Jenkins perform a connection test, connecting to an attacker-specified server with attacker-specified credentials and connection settings.

AI Score

6.6

Confidence

High

EPSS

0.001

Percentile

21.9%

Related for OSV:GHSA-GRMG-5Q49-MQMF