#VU24347 Improper access control in Health Advisor by CloudBees - CVE-2020-2094
Published: January 16, 2020
Health Advisor by CloudBees
Jenkins
Description
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the affected software does not perform permission checks in methods performing form validation. A remote user with Overall/Read access can send an email with fixed content to an attacker-specified recipient.