Description
A server-side request forgery vulnerability exists in Jenkins GitHub Plugin 1.29.0 and older in GitHubPluginConfig.java that allows attackers with Overall/Read access to cause Jenkins to send a GET request to a specified URL.
Remediation
References
https://jenkins.io/security/advisory/2018-06-04/#SECURITY-799
Related Vulnerabilities
CVE-2023-46233 Vulnerability in maven package org.webjars.npm:github-com-brix-crypto-js
CVE-2020-2256 Vulnerability in maven package org.jenkins-ci.plugins:pipeline-maven-parent
CVE-2020-2244 Vulnerability in maven package org.jenkins-ci.plugins:build-failure-analyzer
CVE-2023-33201 Vulnerability in maven package org.bouncycastle:bcprov-debug-jdk15to18
CVE-2021-39236 Vulnerability in maven package org.apache.ozone:ozone-main