Red Hat Bugzilla – Bug 1576712
CVE-2018-1000195 jenkins: Users with Overall/Read permission were able to send GET requests to any URL (SECURITY-794)
Last modified: 2018-08-10 04:09:49 EDT
The form validation code for a tool installer improperly checked permissions, allowing any user with Overall/Read permission to submit a HTTP GET request to any user specified URL, and learn whether the response was successful (HTTP 200) or not. Additionally, this functionality did not require POST requests be used, thereby allowing the above to be performed without direct access to Jenkins via Cross-Site Request Forgery attacks. External References: https://jenkins.io/security/advisory/2018-05-09/
Created jenkins tracking bugs for this issue: Affects: fedora-all [bug 1576715]