Improper access control in Chaos Monkey - CVE-2020-2322
Published: December 3, 2020 / Updated: December 7, 2020
Chaos Monkey
Jenkins
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the affected plugin does not perform permission checks in several HTTP endpoints. A remote user with Overall/Read permission can generate load and generate memory leaks.