Lucene search

K
osvGoogleOSV:GHSA-RV87-VCV4-FJVR
HistoryMay 14, 2022 - 3:05 a.m.

URLTrigger Plugin server-side request forgery vulnerability

2022-05-1403:05:26
Google
osv.dev
4

0.001 Low

EPSS

Percentile

22.0%

A server-side request forgery vulnerability exists in Jenkins URLTrigger Plugin 0.41 and earlier in URLTrigger.java that allows attackers with Overall/Read access to cause Jenkins to send a GET request to a specified URL. As of version 0.43, this form validation method no longer connects to a user provided URL.

0.001 Low

EPSS

Percentile

22.0%

Related for OSV:GHSA-RV87-VCV4-FJVR