Vulnerabilities (CVE)

Filtered by vendor Jenkins Subscribe
Filtered by product Mattermost
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-1003026 1 Jenkins 1 Mattermost 2024-11-21 4.0 MEDIUM 4.3 MEDIUM
A server-side request forgery vulnerability exists in Jenkins Mattermost Notification Plugin 2.6.2 and earlier in MattermostNotifier.java that allows attackers with Overall/Read permission to have Jenkins connect to an attacker-specified Mattermost server and room and send a message.