PT-2018-9357 · Jenkins · Jenkins Cas Plugin+1

Thomas De Grenier De Latour

·

Publicado

2018-06-05

·

Atualizado

2022-05-14

·

CVE-2018-1000188

CVSS v2.0

5.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Jenkins CAS Plugin versions 1.4.1 and older
Description A server-side request forgery issue exists in the CasSecurityRealm.java component, allowing attackers with Overall/Read access to cause the server to send a GET request to a specified URL. This issue is also accompanied by a CSRF vulnerability due to inadequate form validation, which did not initially require POST requests.
Recommendations For Jenkins CAS Plugin versions 1.4.1 and older, update to version 1.4.2 or later, which requires POST requests for form validation and the Overall/Administer permission, mitigating the issue.

Correção

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-1000188
GHSA-F8R7-7HV9-7F43

Produtos afetados

Jenkins
Jenkins Cas Plugin