Missing webhook endpoint authorization in Jenkins Rundeck Plugin
Moderate severity
GitHub Reviewed
Published
Sep 22, 2022
to the GitHub Advisory Database
•
Updated Feb 2, 2023
Description
Published by the National Vulnerability Database
Sep 21, 2022
Published to the GitHub Advisory Database
Sep 22, 2022
Reviewed
Sep 23, 2022
Last updated
Feb 2, 2023
Jenkins Rundeck Plugin 3.6.11 and earlier does not protect access to the
/plugin/rundeck/webhook/
endpoint, allowing users with Overall/Read permission to trigger jobs that are configured to be triggerable via Rundeck.References