{ "id": "CVE-2023-32999", "sourceIdentifier": "jenkinsci-cert@googlegroups.com", "published": "2023-05-16T17:15:12.160", "lastModified": "2023-05-16T19:15:10.207", "vulnStatus": "Received", "descriptions": [ { "lang": "en", "value": "A missing permission check in Jenkins AppSpider Plugin 1.0.15 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL and send an HTTP POST request with a JSON payload consisting of attacker-specified credentials." } ], "metrics": {}, "references": [ { "url": "https://www.jenkins.io/security/advisory/2023-05-16/#SECURITY-3121", "source": "jenkinsci-cert@googlegroups.com" } ] }