Description
A server-side request forgery vulnerability exists in Jenkins GitHub Branch Source Plugin 2.3.4 and older in Endpoint.java that allows attackers with Overall/Read access to cause Jenkins to send a GET request to a specified URL.
Remediation
References
https://jenkins.io/security/advisory/2018-06-04/#SECURITY-806
Related Vulnerabilities
CVE-2022-44621 Vulnerability in maven package org.apache.kylin:kylin-server-base
CVE-2022-41247 Vulnerability in maven package org.jenkins-ci.plugins:bigpanda-jenkins
CVE-2018-12585 Vulnerability in maven package org.opcfoundation.ua:opc-ua-stack
CVE-2015-5319 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2023-31098 Vulnerability in maven package org.apache.inlong:manager-pojo