CVE-2026-57291 Details
Description
Missing permission checks in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allow attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method.
A vulnerability exists in the Jenkins Gitee Plugin in versions through 1288.v18b_deb_c9069b_ that allows attackers with Overall/Read permission to connect to a URL of their choice using credentials IDs obtained through another method. The plugin's HTTP endpoints for global configuration validation lack proper permission checks, enabling this exploitation. Additionally, the absence of POST request requirements creates a cross-site request forgery (CSRF) vulnerability.
Users of the Gitee Plugin should update to version 1292.v2559f2f3f2c0, which includes the necessary permission checks and requires POST requests for the affected HTTP endpoints.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 24, 2026CISA-ADP
Assessed Jun 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.jenkins.io/security/advisory/2026-06-24/#SECURITY-3762%20(1) | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Jenkins Active Directory Plugin | <= 2.41.1 (semver) |
CPE
Remediation
| |
| Jenkins Assembla Plugin | <= 1.4 |
CPE
Remediation
| |
| Jenkins Bitbucket Push and Pull Request Plugin | <= 3.3.8 (semver) |
CPE
Remediation
| |
| Jenkins Contrast Continuous Application Security Plugin | <= 3.11 |
CPE
Remediation
| |
| Jenkins EC2 Fleet Plugin | <= 4.2.3.539.v8fedff2a_81c3 |
CPE
Remediation
| |
| Jenkins External Workspace Manager Plugin | <= 1.3.2 (semver) |
CPE
Remediation
| |
| Jenkins FitNesse Plugin | <= 1.36 |
CPE
Remediation
| |
| Jenkins Git client Plugin | <= 6.6.0 (semver) |
CPE
Remediation
| |
| Jenkins Git Parameter Plugin | <= 462.vdcf3df2ed2ca_ |
CPE
Remediation
| |
| Jenkins Gitee Plugin | <= 1288.v18b_deb_c9069b_ |
CPE
Remediation
| |
| Jenkins GitHub Branch Source Plugin | <= 1967.1969.v205fd594c821 |
CPE
Remediation
| |
| Jenkins Job Configuration History Plugin | <= 1356.ve360da_6c523a_ |
CPE
Remediation
| |
| Jenkins MCP Server Plugin | <= 0.177.v629fdb_2557fe |
CPE
Remediation
| |
| Jenkins OWASP ZAP Plugin | <= 1.0.7 (semver) |
CPE
Remediation
| |
| Jenkins Pipeline: Groovy Plugin | <= 4331.v9d06ed4658ff |
CPE
Remediation
| |
| Jenkins Priority Sorter Plugin | <= 936.v2c01c6b_84449 |
CPE
Remediation
| |
| Jenkins Script Security Plugin | <= 1402.v94c9ce464861 |
CPE
Remediation
| |
| Jenkins Zowe zDevOps Plugin | <= 1.1.3.50.ve350c9b_450b_1 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 24, 2026 | CVE Modified | CISA-ADP |
| Jun 24, 2026 | CVE Modified | CISA-ADP |
| Jun 24, 2026 | New CVE Received | [email protected] |
Volerion