GHSA-76x4-hr82-cg3m
GitHub Security Advisory
Jenkins ElectricFlow Plugin cross-site request forgery vulnerability
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
A missing permission check in a form validation method in CloudBees CD Plugin allowed users with Overall/Read permission to initiate a connection test to an attacker-specified server with attacker-specified username and password.
Additionally, the form validation method did not require POST requests, resulting in a CSRF vulnerability.
This form validation method now requires POST requests and Overall/Administer permissions.
Affected Packages
Maven
org.jenkins-ci.plugins:electricflow
Affected versions:
0
(fixed in 1.1.7)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: August 24, 2025 6:28 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.