A missing permission check in Jenkins iceScrum Plugin prior to version 1.1.6 allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials. This issue is patched in version 1.1.6
{
"nvd_published_at": "2019-10-16T14:15:00Z",
"cwe_ids": [
"CWE-862"
],
"github_reviewed_at": "2022-12-06T21:51:05Z",
"severity": "MODERATE",
"github_reviewed": true
}