#VU65945 Missing Authorization in Coverity - CVE-2022-36921
Published: August 2, 2022
Coverity
Jenkins
Description
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to application does not properly impose security restrictions. A remote user can connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.