#VU65921 Missing Authorization in OpenShift Deployer - CVE-2022-36909
Published: August 2, 2022
OpenShift Deployer
Jenkins
Description
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to application does not properly impose security restrictions. A remote user can check for the existence of an attacker-specified file path on the Jenkins controller file system and upload a SSH key file from the Jenkins controller file system to an attacker-specified URL.