GHSA-mm5c-7mpr-99fm
GitHub Security Advisory
CSRF vulnerability in Jenkins Libvirt Agents Plugin
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
Jenkins Libvirt Agents Plugin 1.9.0 and earlier does not require POST requests for a form submission endpoint, resulting in a cross-site request forgery (CSRF) vulnerability.
This vulnerability allows attackers to stop hypervisor domains.
Jenkins Libvirt Agents Plugin 1.9.1 requires POST requests for the affected HTTP endpoint.
Affected Packages
Maven
org.jenkins-ci.plugins:libvirt-slave
Affected versions:
0
(fixed in 1.9.1)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: August 27, 2025 6:31 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.