jenkins-plugin-git: Server-side request forgery vulnerability (SECURITY-810)
Published Jun 5, 2018
6.4
MEDIUMCVSS 3.0
EPSS 0.81%
Description
A server-side request forgery vulnerability exists in Jenkins Git Plugin 3.9.0 and older in AssemblaWeb.java, GitBlitRepositoryBrowser.java, Gitiles.java, TFS2013GitRepositoryBrowser.java, ViewGitWeb.java that allows attackers with Overall/Read access to cause Jenkins to send a GET request to a specified URL.
Affected products
No data.
No data.
Red Hat OpenShift Container Platform 3.10
jenkins-2-plugins
Will not fix
Red Hat OpenShift Container Platform 3.10
jenkins-plugin-git
Will not fix
Red Hat OpenShift Container Platform 3.11
jenkins-2-plugins
Not affected
Red Hat OpenShift Container Platform 3.4
jenkins-plugin-git
Will not fix
Red Hat OpenShift Container Platform 3.5
jenkins-plugin-git
Will not fix
Red Hat OpenShift Container Platform 3.6
jenkins-plugin-git
Will not fix
Red Hat OpenShift Container Platform 3.7
jenkins-plugin-git
Will not fix
Red Hat OpenShift Container Platform 3.9
jenkins-plugin-git
Will not fix
Red Hat OpenShift Container Platform 4
jenkins-2-plugins
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 3.10 | jenkins-2-plugins | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.10 | jenkins-plugin-git | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.11 | jenkins-2-plugins | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.4 | jenkins-plugin-git | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.5 | jenkins-plugin-git | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.6 | jenkins-plugin-git | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.7 | jenkins-plugin-git | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.9 | jenkins-plugin-git | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | jenkins-2-plugins | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (9)
- https://access.redhat.com/security/cve/CVE-2018-1000182 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1585987 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-2486 Advisory
- https://github.com/advisories/GHSA-53wf-vqf9-cgf2 Advisory
- https://github.com/jenkinsci/git-plugin/commit/87a03f3d9c4a0c0a918d91e173b200a6a3b237a7
- https://jenkins.io/security/advisory/2018-06-04/
- https://jenkins.io/security/advisory/2018-06-04/#SECURITY-810 x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-1000182
- https://www.cve.org/CVERecord?id=CVE-2018-1000182
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub