Description
A server-side request forgery vulnerability exists in Jenkins Kanboard Plugin 1.5.10 and earlier in KanboardGlobalConfiguration.java that allows attackers with Overall/Read permission to submit a GET request to an attacker-specified URL.
Remediation
References
https://jenkins.io/security/advisory/2019-01-28/#SECURITY-818
Related Vulnerabilities
CVE-2019-3797 Vulnerability in maven package org.springframework.data:spring-data-jpa
CVE-2020-2120 Vulnerability in maven package org.jenkins-ci.plugins:fitnesse
CVE-2019-10360 Vulnerability in maven package org.jenkins-ci.plugins.m2release:m2release
CVE-2021-20293 Vulnerability in maven package org.jboss.resteasy:resteasy-core
CVE-2020-16015 Vulnerability in maven package org.webjars.npm:electron