Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
This plugin has been delisted citing unresolved security issues[1]. * Stored XSS vulnerability requiring Overall/Administer permissions. [CVE-2022-23110](https://nvd.nist.gov/vuln/detail/CVE-2022-23110) * CSRF vulnerability. [CVE-2022-23111](https://nvd.nist.gov/vuln/detail/CVE-2022-23111) * Missing permission check allowing connection tests to be performed using only Overall/Read permissions. [CVE-2022-23112](https://nvd.nist.gov/vuln/detail/CVE-2022-23112) * Path traversal vulnerability requiring Item/Configure permissions. [CVE-2022-23113](https://nvd.nist.gov/vuln/detail/CVE-2022-23113) * Password stored in plain text by Publish Over SSH Plugin. [CVE-2022-23114](https://nvd.nist.gov/vuln/detail/CVE-2022-23114) Many of these problems require administrator permissions to leverage but some of them are exploitable without. To mitigate this I plan to block these requests at the nginx reverse proxy layer. [1]: https://www.jenkins.io/security/advisory/2022-01-12/
- Loading branch information