-
CVSS Score
-| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:rundeck | maven | < 3.6.6 | 3.6.6 |
The vulnerability stems from missing authorization checks in form validation methods. The patch added Jenkins.ADMINISTER checks to doTestConnection and Item.CONFIGURE checks to doCheckJobIdentifier, along with @RequirePOST annotations to prevent CSRF. These methods directly handle external connections/credentials validation, aligning with the advisory's description of attackers exploiting missing checks to connect to arbitrary URLs.
A Semantic Attack on Google Gemini - Read the Latest Research