QID 996869
Date Published: 2024-01-31
QID 996869: Java (Maven) Security Update for de.tracetronic.jenkins.plugins:ecutest (GHSA-hp7x-282p-hhr9)
A server-side request forgery vulnerability exists in Jenkins TraceTronic ECU-TEST Plugin 2.3 and earlier in ATXPublisher.java that allows attackers to have Jenkins send HTTP requests to an attacker-specified host.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-hp7x-282p-hhr9 for updates and patch information.
Vendor References
- GHSA-hp7x-282p-hhr9 -
github.com/advisories/GHSA-hp7x-282p-hhr9
CVEs related to QID 996869
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-hp7x-282p-hhr9 | de.tracetronic.jenkins.plugins:ecutest |
|