PT-2018-9351 · Jenkins · Jenkins Git Plugin+1

Thomas De Grenier De Latour

·

Published

2018-06-05

·

Updated

2022-05-14

·

CVE-2018-1000182

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Git Plugin version 3.9.0 and older
Description A server-side request forgery issue exists that allows attackers with Overall/Read access to cause the system to send a GET request to a specified URL. This is due to vulnerabilities in certain Java files, including AssemblaWeb.java, GitBlitRepositoryBrowser.java, Gitiles.java, TFS2013GitRepositoryBrowser.java, and ViewGitWeb.java.
Recommendations For Jenkins Git Plugin version 3.9.0 and older, consider restricting access to sensitive URLs and limiting the Overall/Read permissions to minimize the risk of exploitation. As a temporary workaround, consider disabling the affected Java files until a patch is available.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1000182
GHSA-53WF-VQF9-CGF2

Affected Products

Jenkins
Jenkins Git Plugin