CVE-2018-1999025

HIGH

Jenkins TraceTronic ECU-TEST Plugin <2.3 - SSRF

Title source: llm
STIX 2.1

Description

A man in the middle vulnerability exists in Jenkins TraceTronic ECU-TEST Plugin 2.3 and earlier in ATXPublisher.java, ATXValidator.java that allows attackers to impersonate any service that Jenkins connects to.

References (1)

Core 1
Core References

Scores

CVSS v3 7.4
EPSS 0.0004
EPSS Percentile 12.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-295
Status published
Products (2)
de.tracetronic.jenkins.plugins/ecutest 0 - 2.4Maven
jenkins/tracetronic_ecu-test < 2.3
Published Aug 01, 2018
Tracked Since Feb 18, 2026