PT-2018-9357 · Jenkins · Jenkins Cas Plugin+1
Thomas De Grenier De Latour
·
Publicado
2018-06-05
·
Atualizado
2022-05-14
·
CVE-2018-1000188
CVSS v2.0
5.5
Média
| Vetor | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins CAS Plugin versions 1.4.1 and older
Description
A server-side request forgery issue exists in the CasSecurityRealm.java component, allowing attackers with Overall/Read access to cause the server to send a GET request to a specified URL. This issue is also accompanied by a CSRF vulnerability due to inadequate form validation, which did not initially require POST requests.
Recommendations
For Jenkins CAS Plugin versions 1.4.1 and older, update to version 1.4.2 or later, which requires POST requests for form validation and the Overall/Administer permission, mitigating the issue.
Correção
SSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Jenkins
Jenkins Cas Plugin