Missing Permission Check in Jenkins BearyChat Plugin by Jenkins
CVE-2023-24459
6.5MEDIUM
What is CVE-2023-24459?
The Jenkins BearyChat Plugin prior to version 3.0.3 exhibits a significant security flaw due to a missing permission check. This vulnerability allows attackers with Overall/Read permissions to connect to arbitrary URLs specified by the attacker, potentially leading to unauthorized access and data exfiltration. It is crucial for Jenkins users to update to the latest version to mitigate this risk effectively.
Affected Version(s)
Jenkins BearyChat Plugin <= 3.0.2