QID 997283
Date Published: 2024-02-20
QID 997283: Java (Maven) Security Update for hudson.plugins.octopusdeploy:octopusdeploy (GHSA-5v2j-w677-j4mp)
A server-side request forgery vulnerability exists in Jenkins OctopusDeploy Plugin 1.8.1 and earlier in OctopusDeployPlugin.java that allows attackers with Overall/Read permission to have Jenkins connect to an attacker-specified URL and obtain the HTTP response code if successful, and exception error message otherwise.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-5v2j-w677-j4mp for updates and patch information.
Vendor References
- GHSA-5v2j-w677-j4mp -
github.com/advisories/GHSA-5v2j-w677-j4mp
CVEs related to QID 997283
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-5v2j-w677-j4mp | hudson.plugins.octopusdeploy:octopusdeploy |
|