Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-1000067

Опубликовано: 16 фев. 2018
Источник: debian
EPSS Низкий

Описание

An improper authorization vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to have Jenkins submit HTTP GET requests and get limited information about the response.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
jenkinsremovedpackage

EPSS

Процентиль: 57%
0.00353
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 8 лет назад

An improper authorization vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to have Jenkins submit HTTP GET requests and get limited information about the response.

CVSS3: 6.4
redhat
почти 8 лет назад

An improper authorization vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to have Jenkins submit HTTP GET requests and get limited information about the response.

CVSS3: 5.3
nvd
почти 8 лет назад

An improper authorization vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to have Jenkins submit HTTP GET requests and get limited information about the response.

CVSS3: 5.3
github
больше 3 лет назад

Server-Side Request Forgery in Jenkins

EPSS

Процентиль: 57%
0.00353
Низкий