CVE-2019-16570
Description
A cross-site request forgery vulnerability in Jenkins RapidDeploy Plugin 4.1 and earlier allows attackers to connect to an attacker-specified web server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A CSRF vulnerability in Jenkins RapidDeploy Plugin 4.1 and earlier allows attackers to connect to an attacker-specified web server without authentication.
Vulnerability
Overview
A cross-site request forgery (CSRF) vulnerability exists in the Jenkins RapidDeploy Plugin, versions 4.1 and earlier. The plugin fails to require a POST request for certain form validation endpoints, making it susceptible to CSRF attacks. This allows an attacker to trick an authenticated Jenkins user into unknowingly making a request that connects to an attacker-specified web server [1][2].
Exploitation
To exploit this vulnerability, an attacker must persuade a Jenkins user with at least Overall/Read access to click a crafted link or visit a malicious page while authenticated to Jenkins. The attack does not require any special privileges on the Jenkins instance beyond those of the victim user. Since the vulnerable endpoint does not enforce a POST request, the attacker can exploit a GET-based CSRF [1].
Impact
Successful exploitation results in the Jenkins server connecting to an attacker-controlled web server. While the advisory describes this as connecting to an attacker-specified web server, the exact impact is limited to network reconnaissance or triggering outbound connections. No data leakage or further exploitation on the Jenkins controller is described [1][2].
Mitigation
As of the advisory date (2019-12-17), no fix was released for the RapidDeploy Plugin. The plugin remains listed among those with unresolved security issues. Users are advised to restrict network access from Jenkins to untrusted destinations and monitor for unexpected outbound connections. No workaround within the plugin itself is documented [1][2][3].
AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins:rapiddeploy-jenkinsMaven | <= 4.1 | — |
Affected products
3- Range: <=4.1
- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/advisories/GHSA-922h-8q8g-w7fxghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-16570ghsaADVISORY
- www.openwall.com/lists/oss-security/2019/12/17/1ghsamailing-listx_refsource_MLISTWEB
- jenkins.io/security/advisory/2019-12-17/ghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.