GHSA-p756-66w2-35g7
GitHub Security Advisory
Jenkins Assembla Auth Plugin vulnerable to cross-site request forgery
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
Jenkins Assembla Auth Plugin 1.14 and earlier does not implement a state parameter in its OAuth flow, a unique and non-guessable value associated with each authentication request.
This vulnerability allows attackers to trick users into logging in to the attacker’s account.
Affected Packages
Maven
org.jenkins-ci.plugins:assembla-auth
Affected versions:
0
(last affected: 1.14)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: July 5, 2025 6:26 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.