cbcvebase.
CVE-2018-1999026
published 2018-08-01

CVE-2018-1999026: A server-side request forgery vulnerability exists in Jenkins TraceTronic ECU-TEST Plugin 2.3 and earlier in ATXPublisher.java that allows attackers to have…

medium6.5CVSS 3.0
AVNACLPRLUINSUCNIHAN
A server-side request forgery vulnerability exists in Jenkins TraceTronic ECU-TEST Plugin 2.3 and earlier in ATXPublisher.java that allows attackers to have Jenkins send HTTP requests to an attacker-specified host.

Affected

17 ranges
VendorProductVersion rangeFixed in
jenkinsaccurev_plugin
jenkinsagiletestware_pangolin_connector_for_testrail_plugin
jenkinsanchore_container_image_scanner_plugin
jenkinsconfluence_publisher_plugin
jenkinscredentials_plugin
jenkinsinedo_buildmaster_plugin
jenkinsinedo_proget_plugin
jenkinskubernetes_plugin
jenkinspublish_over_cifs_plugin
jenkinsread_access_to_jenkins_to_override_the_plugin
jenkinsresource_disposer_plugin
jenkinssaltstack_plugin
jenkinsshelve_project_plugin
jenkinsssh_agent_plugin
jenkinstinfoil_security_plugin
jenkinstracetronic_ecu-test<= 2.3
jenkinstracetronic_ecu-test_plugin