Back

MEDIUM

jenkins: Improperly secured form validation for proxy configuration allows Server-Side Request Forgery

Published Feb 16, 2018

Description

An improper authorization vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to have Jenkins submit HTTP GET requests and get limited information about the response.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 16, 2018
Updated Aug 5, 2024
Reserved Feb 15, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Feb 14, 2018
GHSA-6MV9-HCX5-7MHH