A missing permission check in Jenkins ElectricFlow Plugin 1.1.5 and earlier in Configuration#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-10332.json"