MEDIUM
A missing permission check in Jenkins Netsparker Cloud Scan Plugin 1.1.5 and older in the NCScanBuilder.DescriptorImpl#doValidateAPI form validation method allowed attackers with Overall/Read permission to initiate a connection to an attacker-specified server
Published Apr 4, 2019
6.5
MEDIUMCVSS 3.1
EPSS 1.51%
Description
Affected products
Remediation
References (5)
Change history (0)
No recorded changes yet.