CVE-2022-28139

Publication date

2022-03-29 12:30:53

Family

jenkins

State

PUBLISHED

Description

A missing permission check in Jenkins RocketChat Notifier Plugin 1.4.10 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.