CVE-2022-27199
https://notcve.org/view.php?id=CVE-2022-27199
A missing permission check in Jenkins CloudBees AWS Credentials Plugin 189.v3551d5642995 and earlier allows attackers with Overall/Read permission to connect to an AWS service using an attacker-specified token. Una falta de comprobación de permisos en el Plugin CloudBees AWS Credentials de Jenkins versiones 189.v3551d5642995 y anteriores, permite a atacantes con permiso de Overall/Read conectarse a un servicio de AWS usando un token especificado por el atacante • http://www.openwall.com/lists/oss-security/2022/03/15/2 https://www.jenkins.io/security/advisory/2022-03-15/#SECURITY-2351 • CWE-862: Missing Authorization •
CVE-2022-27198
https://notcve.org/view.php?id=CVE-2022-27198
A cross-site request forgery (CSRF) vulnerability in Jenkins CloudBees AWS Credentials Plugin 189.v3551d5642995 and earlier allows attackers with Overall/Read permission to connect to an AWS service using an attacker-specified token. Una vulnerabilidad de tipo cross-site request forgery (CSRF) en el plugin Jenkins CloudBees AWS Credentials versiones 189.v3551d5642995 y anteriores, permite a atacantes con permiso Overall/Read conectarse a un servicio de AWS usando un token especificado por el atacante • http://www.openwall.com/lists/oss-security/2022/03/15/2 https://www.jenkins.io/security/advisory/2022-03-15/#SECURITY-2351 • CWE-352: Cross-Site Request Forgery (CSRF) •