Description
A server-side request forgery vulnerability exists in Jenkins GitHub Plugin 1.29.0 and older in GitHubPluginConfig.java that allows attackers with Overall/Read access to cause Jenkins to send a GET request to a specified URL.
Remediation
References
https://jenkins.io/security/advisory/2018-06-04/#SECURITY-799
Related Vulnerabilities
CVE-2023-29017 Vulnerability in npm package vm2
CVE-2022-36909 Vulnerability in maven package org.jenkins-ci.plugins:openshift-deployer
CVE-2023-33201 Vulnerability in maven package org.bouncycastle:bcprov-ext-jdk14
CVE-2021-41042 Vulnerability in maven package org.eclipse.lyo:lyo-parent
CVE-2023-49377 Vulnerability in maven package com.jfinal:jfinal