Improper access control in Pipeline GitHub Notify Step - CVE-2020-2117
Published: February 13, 2020
Pipeline GitHub Notify Step
Detailed vulnerability description
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the affected software does not perform permission checks on a method implementing form validation. A remote user with Overall/Read access can connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.