Jenkins TraceTronic ECU-TEST Plugin server-side request forgery vulnerability
Moderate severity
GitHub Reviewed
Published
May 14, 2022
to the GitHub Advisory Database
•
Updated Jan 9, 2024
Package
Affected versions
<= 2.3
Patched versions
2.4
Description
Published by the National Vulnerability Database
Aug 1, 2018
Published to the GitHub Advisory Database
May 14, 2022
Last updated
Jan 9, 2024
Reviewed
Jan 9, 2024
A server-side request forgery vulnerability exists in Jenkins TraceTronic ECU-TEST Plugin 2.3 and earlier in ATXPublisher.java that allows attackers to have Jenkins send HTTP requests to an attacker-specified host.
References