MEDIUM
jenkins: Users with Overall/Read permission were able to send GET requests to any URL (SECURITY-794)
Published Jun 5, 2018
4.3
MEDIUMCVSS 3.1
EPSS 2.07%
Description
A server-side request forgery vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in ZipExtractionInstaller.java that allows users with Overall/Read permission to have Jenkins submit a HTTP GET request to an arbitrary URL and learn whether the response is successful (200) or not.
Affected products
No data.
No data.
Red Hat OpenShift Enterprise 3
jenkins
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Enterprise 3 | jenkins | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (10)
- https://access.redhat.com/security/cve/CVE-2018-1000195 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1576712 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-5170 Advisory
- https://github.com/advisories/GHSA-rgmj-mccj-h9mx Advisory
- https://github.com/jenkinsci/jenkins/commit/6eea1e97840b5623829b2c1fd2e363c045bdc230
- https://jenkins.io/security/advisory/2018-05-09/
- https://jenkins.io/security/advisory/2018-05-09/#SECURITY-794 x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-1000195
- https://www.cve.org/CVERecord?id=CVE-2018-1000195
- https://www.oracle.com/security-alerts/cpuapr2022.html x_refsource_MISCPatchThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2018-1000195 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1576712 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-5170 | Advisory | |
| https://github.com/advisories/GHSA-rgmj-mccj-h9mx | Advisory | |
| https://github.com/jenkinsci/jenkins/commit/6eea1e97840b5623829b2c1fd2e363c045bdc230 | ||
| https://jenkins.io/security/advisory/2018-05-09/ | ||
| https://jenkins.io/security/advisory/2018-05-09/#SECURITY-794 | x_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-1000195 | ||
| https://www.cve.org/CVERecord?id=CVE-2018-1000195 | ||
| https://www.oracle.com/security-alerts/cpuapr2022.html | x_refsource_MISCPatchThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 5, 2018
Updated Aug 5, 2024
Reserved May 9, 2018
Link CVE-2018-1000195
CISA Vulnrichment
No data
GitHub
Link GHSA-RGMJ-MCCJ-H9MX