PT-2018-9357 · Jenkins · Jenkins Cas Plugin+1

Thomas De Grenier De Latour

·

Published

2018-06-05

·

Updated

2022-05-14

·

CVE-2018-1000188

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Jenkins CAS Plugin versions 1.4.1 and older
Description A server-side request forgery issue exists in the CasSecurityRealm.java component, allowing attackers with Overall/Read access to cause the server to send a GET request to a specified URL. This issue is also accompanied by a CSRF vulnerability due to inadequate form validation, which did not initially require POST requests.
Recommendations For Jenkins CAS Plugin versions 1.4.1 and older, update to version 1.4.2 or later, which requires POST requests for form validation and the Overall/Administer permission, mitigating the issue.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1000188
GHSA-F8R7-7HV9-7F43

Affected Products

Jenkins
Jenkins Cas Plugin