#VU25287 Improper access control in Pipeline GitHub Notify Step - CVE-2020-2117
Published: February 13, 2020
Pipeline GitHub Notify Step
Jenkins
Description
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the affected software does not perform permission checks on a method implementing form validation. A remote user with Overall/Read access can connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.