Loading HuntDB...

GHSA-38pm-74xc-phcw

GitHub Security Advisory

CSRF vulnerability in Jenkins XebiaLabs XL Deploy Plugin allows capturing credentials

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

A cross-site request forgery (CSRF) vulnerability in Jenkins XebiaLabs XL Deploy Plugin 10.0.1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing Username/password credentials stored in Jenkins.

Jenkins XebiaLabs XL Deploy Plugin 10.0.2 requires POST requests and Overall/Administer permission for the affected form validation method.

Affected Packages

Maven com.xebialabs.deployit.ci:deployit-plugin
Affected versions: 0 (fixed in 10.0.2)

Related CVEs

Key Information

GHSA ID
GHSA-38pm-74xc-phcw
Published
May 24, 2022 7:04 PM
Last Modified
October 27, 2023 3:01 PM
CVSS Score
7.5 /10
Primary Ecosystem
Maven
Primary Package
com.xebialabs.deployit.ci:deployit-plugin
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 24, 2025 6:28 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.