CVE-2018-1000188
05.06.2018, 20:29
A server-side request forgery vulnerability exists in Jenkins CAS Plugin 1.4.1 and older in CasSecurityRealm.java that allows attackers with Overall/Read access to cause Jenkins to send a GET request to a specified URL.
Vendor | Product | Version |
---|---|---|
jenkins | cas | 𝑥 ≤ 1.4.1 |
𝑥
= Vulnerable software versions