CVE-2022-25195

Missing Authorization in maven/io.jenkins.plugins/autonomiq

Identifiers

GHSA-6jv7-28mv-qp9c, CVE-2022-25195

Package Slug

maven/io.jenkins.plugins/autonomiq

Vulnerability

Missing Authorization

Description

A missing permission check in Jenkins autonomiq Plugin 1.15 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.

Affected Versions

All versions before 1.16

Solution

Upgrade to version 1.16 or above.

Last Modified

2022-05-05

source