PT-2018-9351 · Jenkins · Jenkins Git Plugin+1

Thomas De Grenier De Latour

·

Publicado

2018-06-05

·

Atualizado

2022-05-14

·

CVE-2018-1000182

CVSS v3.1

6.4

Média

VetorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Git Plugin version 3.9.0 and older
Description A server-side request forgery issue exists that allows attackers with Overall/Read access to cause the system to send a GET request to a specified URL. This is due to vulnerabilities in certain Java files, including AssemblaWeb.java, GitBlitRepositoryBrowser.java, Gitiles.java, TFS2013GitRepositoryBrowser.java, and ViewGitWeb.java.
Recommendations For Jenkins Git Plugin version 3.9.0 and older, consider restricting access to sensitive URLs and limiting the Overall/Read permissions to minimize the risk of exploitation. As a temporary workaround, consider disabling the affected Java files until a patch is available.

Correção

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-1000182
GHSA-53WF-VQF9-CGF2

Produtos afetados

Jenkins
Jenkins Git Plugin