Jenkins Cross-Site Request Forgery (CSRF) Vulnerability - CVE-2018-1000195 - Vulnerability Database

Jenkins Cross-Site Request Forgery (CSRF) Vulnerability - CVE-2018-1000195

Medium
Reference: CVE-2018-1000195
Title: Jenkins Cross-Site Request Forgery (CSRF) Vulnerability
Overview:

A server-side request forgery vulnerability exists in Jenkins 2.120 and older LTS 2.107.2 and older in ZipExtractionInstaller.java that allows users with Overall/Read permission to have Jenkins submit a HTTP GET request to an arbitrary URL and learn whether the response is successful (200) or not.