A confused deputy vulnerability exists in Jenkins Publisher Over CIFS Plugin 0.10 and earlier in CifsPublisherPluginDescriptor.java that allows attackers to have Jenkins connect to an attacker specified CIFS server with attacker specified credentials.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-10-03T16:22:22

Updated: 2022-10-03T16:22:22

Reserved: 2018-07-30T00:00:00


Link: CVE-2018-1999038

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-08-01T13:29:00.967

Modified: 2018-10-15T15:32:13.397


Link: CVE-2018-1999038

JSON object: View

cve-icon Redhat Information

No data.

CWE