Medium severity4.3NVD Advisory· Published Jun 5, 2018· Updated Jun 17, 2026
CVE-2018-1000195
CVE-2018-1000195
Description
A server-side request forgery vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in ZipExtractionInstaller.java that allows users with Overall/Read permission to have Jenkins submit a HTTP GET request to an arbitrary URL and learn whether the response is successful (200) or not.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.main:jenkins-coreMaven | < 2.107.3 | 2.107.3 |
org.jenkins-ci.main:jenkins-coreMaven | >= 2.108, < 2.121 | 2.121 |
Affected products
1Patches
Vulnerability mechanics
References
5- www.oracle.com/security-alerts/cpuapr2022.htmlnvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-rgmj-mccj-h9mxghsaADVISORY
- jenkins.io/security/advisory/2018-05-09/nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2018-1000195ghsaADVISORY
- github.com/jenkinsci/jenkins/commit/6eea1e97840b5623829b2c1fd2e363c045bdc230ghsaWEB
News mentions
0No linked articles in our index yet.