QID 996872
Date Published: 2024-02-05
QID 996872: Java (Maven) Security Update for com.coravy.hudson.plugins.github:github (GHSA-gh85-mq87-r7v3)
A server-side request forgery vulnerability exists in Jenkins GitHub Plugin 1.29.0 and older in GitHubPluginConfig.java that allows attackers with Overall/Read access to cause Jenkins to send a GET request to a specified URL.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-gh85-mq87-r7v3 for updates and patch information.
Vendor References
- GHSA-gh85-mq87-r7v3 -
github.com/advisories/GHSA-gh85-mq87-r7v3
CVEs related to QID 996872
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-gh85-mq87-r7v3 | com.coravy.hudson.plugins.github:github |
|