CVE-2019-1003026
20.02.2019, 21:29
A server-side request forgery vulnerability exists in Jenkins Mattermost Notification Plugin 2.6.2 and earlier in MattermostNotifier.java that allows attackers with Overall/Read permission to have Jenkins connect to an attacker-specified Mattermost server and room and send a message.
Vendor | Product | Version |
---|---|---|
jenkins | mattermost | 𝑥 ≤ 2.6.2 |
𝑥
= Vulnerable software versions