Jenkins Assembla Plugin has a missing permission check
Moderate severity
GitHub Reviewed
Published
Jun 24, 2026
to the GitHub Advisory Database
•
Updated Sep 25, 2026
Description
Published by the National Vulnerability Database
Jun 24, 2026
Published to the GitHub Advisory Database
Jun 24, 2026
Reviewed
Sep 25, 2026
Last updated
Sep 25, 2026
Jenkins Assembla Plugin 1.4 and earlier does not perform a permission check in an HTTP endpoint that tests the connection to an Assembla server.
This allows attackers with Overall/Read permission to connect to an attacker-specified URL using an attacker-specified username and password.
Additionally, this HTTP endpoint does not require POST requests, resulting in a cross-site request forgery (CSRF) vulnerability.
As of publication of this advisory, there is no fix.
References