Source |
CVE Liste |
Identifiant |
4670394 |
Date de publication |
2022-05-17 15:15:09 (vue: 2022-05-17 17:06:37) |
Titre |
CVE-2022-30954 |
Texte |
Jenkins Blue Ocean Plugin 1.25.3 and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified HTTP server. |
Notes |
★★★★★
|
Envoyé |
Oui |
Condensat |
2022 30954 allowing attacker attackers blue check connect cve does earlier endpoints http jenkins not ocean overall/read perform permission plugin server several specified |
Tags |
|
Stories |
APT 32
|
Move |
|