Description
A server-side request forgery vulnerability exists in Jenkins Kanboard Plugin 1.5.10 and earlier in KanboardGlobalConfiguration.java that allows attackers with Overall/Read permission to submit a GET request to an attacker-specified URL.
Remediation
References
https://jenkins.io/security/advisory/2019-01-28/#SECURITY-818
Related Vulnerabilities
CVE-2023-24427 Vulnerability in maven package org.jenkins-ci.plugins:bitbucket-oauth
CVE-2022-40764 Vulnerability in npm package snyk
CVE-2011-0533 Vulnerability in maven package org.apache.continuum:continuum-webapp
CVE-2018-1000149 Vulnerability in maven package org.jenkins-ci.plugins:ansible
CVE-2023-31141 Vulnerability in maven package org.opensearch.plugin:opensearch-security