#VU51997 Improper access control in Micro Focus Application Automation Tools - CVE-2021-22513
Published: April 8, 2021
Micro Focus Application Automation Tools
Jenkins
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the affected plugin does not perform permission checks in methods implementing form validation. A remote authenticated attacker can connect to attacker-specified URLs using attacker-specified username and password.