GHSA-cp6q-836q-gmj3
GitHub Security Advisory
Cross-Site Request Forgery in Jenkins Failed Job Deactivator Plugin
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
A cross-site request forgery (CSRF) vulnerability in Jenkins Failed Job Deactivator Plugin 1.2.1 and earlier allows attackers to disable jobs. This CSRF vulnerability is only exploitable in Jenkins 2.286 and earlier, LTS 2.277.1 and earlier. See the [LTS upgrade guide](https://www.jenkins.io/doc/upgrade-guide/2.277/#upgrading-to-jenkins-lts-2-277-2).
Affected Packages
Maven
de.einsundeins.jenkins.plugins.failedjobdeactivator:failedJobDeactivator
Affected versions:
0
(last affected: 1.2.1)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: August 25, 2025 6:33 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.