Back

MEDIUM

jenkins: Users with Overall/Read permission were able to send GET requests to any URL (SECURITY-794)

Published Jun 5, 2018

Description

A server-side request forgery vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in ZipExtractionInstaller.java that allows users with Overall/Read permission to have Jenkins submit a HTTP GET request to an arbitrary URL and learn whether the response is successful (200) or not.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (2)

References (10)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published Jun 5, 2018
Updated Aug 5, 2024
Reserved May 9, 2018

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Low
Public date May 9, 2018
Bugzilla 1576712

ENISA EUVD

Assigner mitre
Published Jun 5, 2018
Updated Aug 5, 2024