#VU46955 Improper access control in ElasTest - CVE-2020-2272
Published: September 16, 2020 / Updated: May 3, 2021
ElasTest
Jenkins
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the affected plugin does not perform a permission check in a method implementing form validation. A remote user with Overall/Read permission can connect to an attacker-specified URL using attacker-specified credentials.