GHSA-grpp-gx5h-pvh8
GitHub Security Advisory
Jenkins XebiaLabs XL Deploy Plugin vulnerable to Cross-site request forgery (CSRF)
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
A missing permission check in a form validation method in Jenkins XebiaLabs XL Deploy Plugin allows users with Overall/Read permission to initiate a connection test to an attacker-specified server with attacker-specified credentials.
Additionally, the form validation method does not require POST requests, resulting in a CSRF vulnerability.
Affected Packages
Maven
com.xebialabs.deployit.ci:deployit-plugin
Affected versions:
0
(fixed in 7.5.5)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 6, 2025 6:30 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.