CVE-2019-1003058
Description
A cross-site request forgery vulnerability in Jenkins FTP publisher Plugin in the FTPPublisher.DescriptorImpl#doLoginCheck method allows attackers to initiate a connection to an attacker-specified server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
CSRF in Jenkins FTP publisher Plugin allows attackers to initiate connections to attacker-specified servers via the doLoginCheck method.
Vulnerability
A cross-site request forgery (CSRF) vulnerability exists in the Jenkins FTP publisher Plugin in the FTPPublisher.DescriptorImpl#doLoginCheck method [1][2][3]. This flaw allows an attacker to perform actions on behalf of an authenticated Jenkins user, specifically initiating a connection to an attacker-specified server. The affected plugin version(s) are those included in Jenkins installations prior to the security advisory released on 2019-04-03 [1].
Exploitation
To exploit this vulnerability, an attacker must trick a Jenkins user with the necessary permissions into visiting a malicious web page or link [1][2]. No special network position is required; the attack is performed via a standard web browser. The attacker crafts a request that targets the doLoginCheck method, causing the victim's browser to send the forged request, which then initiates a connection to a server specified by the attacker [1][3].
Impact
Successful exploitation allows the attacker to cause the Jenkins controller to initiate a connection to an attacker-specified server [1][3]. This could lead to information disclosure if the server captures data sent during the connection, or be used as a stepping stone for further attacks. The impact is constrained to the network connection initiation; however, the specific consequences depend on the attacker's server and the data transmitted [1].
Mitigation
Jenkins released a security advisory on 2019-04-03 [1]. Users should update the FTP publisher Plugin to a version that includes the fix for this vulnerability. As of the advisory, no specific workaround is mentioned [1]. The CVE is not listed in the Known Exploited Vulnerabilities (KEV) catalog at this time.
AI Insight generated on May 22, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jvnet.hudson.plugins:ftppublisherMaven | <= 1.2 | — |
Affected products
3- Range: all versions as of 2019-04-03
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- github.com/advisories/GHSA-wg7x-vf54-9qjwghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-1003058ghsaADVISORY
- www.openwall.com/lists/oss-security/2019/04/12/2ghsamailing-listx_refsource_MLISTWEB
- www.securityfocus.com/bid/107790ghsavdb-entryx_refsource_BIDWEB
- jenkins.io/security/advisory/2019-04-03/ghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.