CVE-2019-1003027: SSRF
A server-side request forgery vulnerability exists in Jenkins OctopusDeploy Plugin 1.8.1 and earlier in OctopusDeployPlugin.java that allows attackers with Overall/Read permission to have Jenkins connect to an attacker-specified URL and obtain the HTTP response code if successful, and exception error message otherwise.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1003027?
CVE-2019-1003027 is considered to have a medium severity as it allows server-side request forgery.
How do I fix CVE-2019-1003027?
To fix CVE-2019-1003027, upgrade the Jenkins OctopusDeploy Plugin to version 1.9.0 or later.
What versions of the OctopusDeploy Plugin are affected by CVE-2019-1003027?
Versions 1.8.1 and earlier of the OctopusDeploy Plugin are affected by CVE-2019-1003027.
Who is affected by CVE-2019-1003027?
Any Jenkins user with Overall/Read permission can be affected by CVE-2019-1003027.
What type of vulnerability is CVE-2019-1003027?
CVE-2019-1003027 is classified as a server-side request forgery (SSRF) vulnerability.