Loading HuntDB...

GHSA-7g7g-82fp-hpxx

GitHub Security Advisory

CSRF vulnerability in Jenkins SCP publisher Plugin

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

SCP publisher Plugin 1.8 and earlier does not perform a permission check in a method implementing form validation.

This allows attackers with Overall/Read permission to connect to an attacker-specified SSH server using attacker-specified credentials.

Additionally, this form validation method does not require POST requests, resulting in a cross-site request forgery (CSRF) vulnerability.

Affected Packages

Maven org.jenkins-ci.plugins:scp
Affected versions: 0 (last affected: 1.8)

Related CVEs

Key Information

GHSA ID
GHSA-7g7g-82fp-hpxx
Published
February 16, 2022 12:01 AM
Last Modified
October 27, 2023 4:50 PM
CVSS Score
7.5 /10
Primary Ecosystem
Maven
Primary Package
org.jenkins-ci.plugins:scp
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 27, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.