GHSA-fq56-wvv2-p8jf

Suggest an improvement
Source
https://github.com/advisories/GHSA-fq56-wvv2-p8jf
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-fq56-wvv2-p8jf/GHSA-fq56-wvv2-p8jf.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-fq56-wvv2-p8jf
Aliases
  • CVE-2026-57290
Published
2026-06-24T15:31:47Z
Modified
2026-09-25T19:15:04Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N CVSS Calculator
Summary
Jenkins Priority Sorter Plugin has a CSRF vulnerability
Details

Jenkins Priority Sorter Plugin 936.v2c01c6b_84449 and earlier does not require POST requests in an HTTP endpoint that saves the global job priority configuration.

This allows attackers to overwrite the global job priority configuration.

Priority Sorter Plugin 936.937.v5581d0b_2ccb_a_ requires POST requests for the affected HTTP endpoint.

Database specific
{
    "cwe_ids":  [
        "CWE-352"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-09-25T19:07:38Z",
    "nvd_published_at":  "2026-06-24T14:17:35Z",
    "severity":  "MODERATE"
}
References

Affected packages

Maven / org.jenkins-ci.plugins:PrioritySorter

Package

Name
org.jenkins-ci.plugins:PrioritySorter
View open source insights on deps.dev
Purl
pkg:maven/org.jenkins-ci.plugins/PrioritySorter

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
936.937.v5581d0b

Affected versions

2.*
2.0-beta-1
2.0-beta-2
2.0-beta-3
2.0
2.1
2.2
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2.11
2.12
3.*
3.0-beta-1
3.0-beta-2
3.0
3.1
3.2
3.3
3.4
3.4.1
3.5.0
3.5.1
3.6.0
4.*
4.0.0
4.0.1
4.1.0
5.*
5.0.0
5.1.0
5.2.0
5.3.0
849.*
849.v459ea_77d16d4
861.*
861.v1a_e68e5f9285
863.*
863.v4a_b_974a_5d042
905.*
905.v35c21f62f980
936.*
936.v2c01c6b_84449

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-fq56-wvv2-p8jf/GHSA-fq56-wvv2-p8jf.json"