A missing permission check in Jenkins CloudBees AWS Credentials Plugin 189.v3551d5642995 and earlier allows attackers with Overall/Read permission to connect to an AWS service using an attacker-specified token.
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon
- https://github.com/jenkinsci-cert/nvd-cwe