CVE-2018-1000182

CVSS v3.0 6.4 (Medium)
64% Progress
CVSS v2.0 5.5 (Medium)
55% Progress
EPSS 0.05 % (22th)
0.05% Progress
Affected Products 1
Advisories 3

A server-side request forgery vulnerability exists in Jenkins Git Plugin 3.9.0 and older in AssemblaWeb.java, GitBlitRepositoryBrowser.java, Gitiles.java, TFS2013GitRepositoryBrowser.java, ViewGitWeb.java that allows attackers with Overall/Read access to cause Jenkins to send a GET request to a specified URL.

Weaknesses
CWE-918
Server-Side Request Forgery (SSRF)
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2018-06-05 20:29:00
(6 years ago)
Updated Date
2018-07-18 18:06:06
(6 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Jenkins Git for Jenkins 3.9.0 and prior versions cpe:2.3:a:jenkins:git::*:*:*:*:jenkins <= 3.9.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...