GHSA-72c8-3wwg-r59w

Suggest an improvement
Source
https://github.com/advisories/GHSA-72c8-3wwg-r59w
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-72c8-3wwg-r59w/GHSA-72c8-3wwg-r59w.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-72c8-3wwg-r59w
Aliases
Published
2026-06-24T15:31:47Z
Modified
2026-09-25T18:15:04Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
Jenkins Pipeline: Groovy Plugin has a CSRF vulnerability
Details

Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier does not restrict the types that can be instantiated through the Pipeline Snippet Generator, instantiating any type with a constructor annotated with @DataBoundConstructor in response to a request.

This allows attackers to have Pipeline: Groovy Plugin instantiate types related to job or system configuration other than Pipeline steps.

Additionally, this HTTP endpoint can be accessed using the GET method and does not require POST requests, resulting in a cross-site request forgery (CSRF) vulnerability. This allows attackers to create a script approval request attributed to another user, impersonating a trusted user when social engineering an administrator into approving a malicious script.

This vulnerability has been reported through the Jenkins Bug Bounty Program sponsored by the European Commission. Pipeline: Groovy Plugin 4331.4333.v50a_b_076c5199 only instantiates Pipeline steps and metastep delegates through the Snippet Generator, and requires POST requests for the affected HTTP endpoint.

Database specific
{
    "cwe_ids":  [
        "CWE-352"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-09-25T18:09:24Z",
    "nvd_published_at":  "2026-06-24T14:17:34Z",
    "severity":  "MODERATE"
}
References

Affected packages

Maven / io.jenkins.plugins:pipeline-groovy-lib

Package

Name
io.jenkins.plugins:pipeline-groovy-lib
View open source insights on deps.dev
Purl
pkg:maven/io.jenkins.plugins/pipeline-groovy-lib

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4331.4333

Affected versions

589.*
589.vb_a_b_4a_a_8c443c
591.*
591.v3a_7f422b_d058
593.*
593.va_a_fc25d520e9
593.595.vfc6485d13dcd
598.*
598.vcd66b_a_336510
612.*
612.v84da_9c54906d
612.614.v48dcb_f62a_640
613.*
613.v9c41a_160233f
621.*
621.vb_44ce045b_582
629.*
629.vb_5627b_ee2104
656.*
656.va_a_ceeb_6ffb_f7
671.*
671.v07c339c842e8
673.*
673.vb_c5d5948283c
685.*
685.v8ee9ed91d574
687.*
687.v62591d623759
689.*
689.veec561a_dee13
700.*
700.v0e341fa_57d53
704.*
704.vc58b_8890a_384
710.*
710.v4b_94b_077a_808
727.*
727.ve832a_9244dfa_
730.*
730.ve57b_34648c63
740.*
740.va_2701257fe8d
744.*
744.v5b_556ee7c253
745.*
745.vdf6077913de0
749.*
749.v70084559234a_
751.*
751.v709f84f7d768
752.*
752.vdddedf804e72
763.*
763.v13008816b_de7
766.*
766.v2b_e08c2e6ff2
776.*
776.vfee5327b_b_a_5b_
787.*
787.ve2fef0efdca_6
797.*
797.v90ea_a_9b_e45a_0
798.*
798.v5cc688825312
805.*
805.va_fc79344957d
806.*
806.v408277b_33d1d

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-72c8-3wwg-r59w/GHSA-72c8-3wwg-r59w.json"