GHSA-35r9-gfqf-r6cw

Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/06/GHSA-35r9-gfqf-r6cw/GHSA-35r9-gfqf-r6cw.json
Aliases
  • CVE-2022-34212
Published
2022-06-24T00:00:32Z
Modified
2023-03-18T05:54:46.865104Z
Details

A missing permission check in Jenkins vRealize Orchestrator Plugin 3.0 and earlier allows attackers with Overall/Read permission to send an HTTP POST request to an attacker-specified URL.

References

Affected packages

Maven / org.jenkins-ci.plugins:vmware-vrealize-orchestrator

org.jenkins-ci.plugins:vmware-vrealize-orchestrator

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0

Affected versions

1.*

1.0
1.1

2.*

2.0

3.*

3.0

Database specific

{
    "last_known_affected_version_range": "<= 3.0"
}