A missing permission check in Jenkins SOASTA CloudTest Plugin in the CloudTestServer.DescriptorImpl#doValidate form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
jenkins soasta cloudtest |