CVE-2019-16569
Description
A cross-site request forgery vulnerability in Jenkins Mantis Plugin 0.26 and earlier allows attackers to connect to an attacker-specified web server using attacker-specified credentials.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A cross-site request forgery vulnerability in Jenkins Mantis Plugin 0.26 and earlier allows attackers to connect to an attacker-specified server using attacker-controlled credentials.
Vulnerability
Description
Jenkins Mantis Plugin versions 0.26 and earlier are vulnerable to a cross-site request forgery (CSRF) flaw. The plugin does not properly validate requests, allowing an attacker to trick a Jenkins user with sufficient permissions into making an unintended request [1].
Exploitation
An attacker can exploit this CSRF vulnerability to cause Jenkins to connect to an attacker-specified web server using attacker-specified credentials [2]. This requires the victim to be authenticated and to click a malicious link or visit a crafted webpage while logged into Jenkins. The attack does not require any special privileges beyond those of the victim user.
Impact
Successful exploitation could allow the attacker to perform actions such as sending sensitive Jenkins data to an external server or using Jenkins as a proxy to launch further attacks [1][2]. The specific impact depends on the attacker's objectives, but could include information disclosure or resource abuse.
Mitigation
Jenkins has acknowledged the vulnerability but no fix has been released as of the advisory [2][3]. Users are advised to restrict access to Jenkins or disable the Mantis Plugin if possible until a patch becomes available.
AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins:mantisMaven | <= 0.26 | — |
Affected products
3- Range: <=0.26
- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/advisories/GHSA-wwrr-4jp4-58wgghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-16569ghsaADVISORY
- www.openwall.com/lists/oss-security/2019/12/17/1ghsamailing-listx_refsource_MLISTWEB
- jenkins.io/security/advisory/2019-12-17/ghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.