漏洞描述
Jenkins GitHub Plugin 1.29.1 and earlier is susceptible to server-side request forgery via GitHubTokenCredentialsCreator.java, which allows attackers to leverage attacker-specified credentials IDs obtained through another method and capture the credentials stored in Jenkins.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
www.jenkins.iohttps://www.jenkins.io/security/advisory/2018-06-25/#SECURITY-915↗devco.rehttps://devco.re/blog/2019/01/16/hacking-Jenkins-part1-play-with-dynamic-routing/↗jenkins.iohttps://jenkins.io/security/advisory/2018-06-25/#SECURITY-915↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2018-1000600↗github.comhttps://github.com/ARPSyndicate/kenzer-templates↗