Description
A server-side request forgery vulnerability exists in Jenkins Confluence Publisher Plugin 2.0.1 and earlier in ConfluenceSite.java that allows attackers to have Jenkins submit login requests to an attacker-specified Confluence server URL with attacker specified credentials.
Remediation
References
https://jenkins.io/security/advisory/2018-07-30/#SECURITY-982
Related Vulnerabilities
CVE-2015-3250 Vulnerability in maven package org.apache.directory.api:api-ldap-model
CVE-2023-31103 Vulnerability in maven package org.apache.inlong:manager-dao
CVE-2018-14042 Vulnerability in maven package org.webjars.npm:bootstrap
CVE-2017-8032 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-uaa
CVE-2022-39203 Vulnerability in npm package matrix-appservice-irc