CVE-2018-1000185: SSRF
A server-side request forgery vulnerability exists in Jenkins GitHub Branch Source Plugin 2.3.4 and older in Endpoint.java that allows attackers with Overall/Read access to cause Jenkins to send a GET request to a specified URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1000185?
CVE-2018-1000185 is classified as a medium severity vulnerability due to its potential impact on server-side request forgery.
How do I fix CVE-2018-1000185?
To fix CVE-2018-1000185, upgrade Jenkins GitHub Branch Source Plugin to version 2.3.5 or later.
Who is affected by CVE-2018-1000185?
CVE-2018-1000185 affects users of Jenkins GitHub Branch Source Plugin version 2.3.4 and older.
What type of vulnerability is CVE-2018-1000185?
CVE-2018-1000185 is a server-side request forgery vulnerability that allows attackers to send unauthorized requests.
What access is required to exploit CVE-2018-1000185?
Exploitation of CVE-2018-1000185 requires the attacker to have Overall/Read access to the Jenkins instance.