fig. 01 — GHSA-77vq-4j66-46m5, the advisory selected below
// advisories
GHSA-77vq-4j66-46m5
MODERATECVE-2022-34210
A missing permission check in Jenkins ThreadFix Plugin 1.5.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL.