Loading HuntDB...

GHSA-vx6r-w45x-q3h6

GitHub Security Advisory

Jenkins Kubernetes CI/CD Plugin vulnerable to Cross-Site Request Forgery

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

A cross-site request forgery vulnerability in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

## Note: Jenkins has suspended distribution of this plugin.

Affected Packages

Maven com.elasticbox.jenkins-ci.plugins:kubernetes-ci
Affected versions: 0 (last affected: 1.3)

Related CVEs

Key Information

GHSA ID
GHSA-vx6r-w45x-q3h6
Published
May 24, 2022 4:59 PM
Last Modified
December 6, 2022 9:39 PM
CVSS Score
7.5 /10
Primary Ecosystem
Maven
Primary Package
com.elasticbox.jenkins-ci.plugins:kubernetes-ci
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 5, 2025 6:26 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.