GHSA-5gwh-r76w-934h
MODERATECVE-2023-6149Qualys Jenkins Plugin for WAS prior to version and including 2.0.11 was identified to be affected by a security flaw, which was missing a permission check while performing a connectivity check to Qualys Cloud Services. This allowed any user with login access to configure or edit jobs to utilize the plugin and configure potential a rouge endpoint via which it was possible to control response for ce
- Affected
- <= 2.0.11
- Fixed in
- 2.0.12
- Weakness
- CWE-611
- Published
- 2024-01-09
- Source
- github