GHSA-jhcq-6wqp-qcfx

Suggest an improvement
Source
https://github.com/advisories/GHSA-jhcq-6wqp-qcfx
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-jhcq-6wqp-qcfx/GHSA-jhcq-6wqp-qcfx.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-jhcq-6wqp-qcfx
Aliases
  • CVE-2026-57293
Published
2026-06-24T15:31:47Z
Modified
2026-09-25T19:15:04Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Jenkins Gitee Plugin has an incorrect permission check that allows enumerating credentials IDs
Details

Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier does not correctly perform a permission check in an HTTP endpoint.

This allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credentials IDs of credentials stored in Jenkins. Those can be used as part of an attack to capture the credentials using another vulnerability.

An enumeration of credentials IDs in Gitee Plugin 1292.v2559f2f3f2c0 requires Overall/Administer permission.

Database specific
{
    "cwe_ids":  [
        "CWE-862"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-09-25T19:05:28Z",
    "nvd_published_at":  "2026-06-24T14:17:35Z",
    "severity":  "MODERATE"
}
References

Affected packages

Maven / org.jenkins-ci.plugins:gitee

Package

Name
org.jenkins-ci.plugins:gitee
View open source insights on deps.dev
Purl
pkg:maven/org.jenkins-ci.plugins/gitee

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1292.v2559f2f3f2c0

Affected versions

1.*
1.0.11
1.0.12
1.0.13
1.0.14
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.7
1.1.8
1.1.9
1.1.10
1.1.11
1.1.12
1.1.13
1.1.14
1.1.15
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1164.*
1164.v92b_911c15f28
1165.*
1165.vd01443918414
1170.*
1170.v3d4640b_34233
1189.*
1189.v6cb_10c9d63b_8
1190.*
1190.v317d91b_3a_4e2
1195.*
1195.ve7a_e26d4a_898
1197.*
1197.v2a_b_30a_0982b_7
1198.*
1198.vf35a_c423421e
1201.*
1201.vc0f481dff802
1204.*
1204.v4635f4272c96
1224.*
1224.v843da_c08c504
1232.*
1232.v1f6eca_6f587e
1245.*
1245.vb_39c7f51d6b_2
1246.*
1246.va_96d8b_79c02f
1247.*
1247.v3cf071d5ff46
1250.*
1250.vef5eeda_60678
1251.*
1251.vb_37e0d6e1b_e7
1252.*
1252.v891b_4e5f0303
1253.*
1253.vb_5564dd738c8
1255.*
1255.v1b_42e96a_378b_
1256.*
1256.ve06b_0354a_c88
1257.*
1257.v94e12c8783d7
1258.*
1258.v1a_3914c28c90
1259.*
1259.va_7b_c7a_46a_79d
1260.*
1260.v88b_b_167e8cb_7
1261.*
1261.v9f3fef7e413b_
1265.*
1265.va_1ef8dc4329f
1266.*
1266.v5743e3349d54
1271.*
1271.vf8493ca_07721
1272.*
1272.v583461cd985b_
1277.*
1277.v4988370637e3
1278.*
1278.v35c10a_5844c0
1282.*
1282.vcb_38e525f3c5
1288.*
1288.v18b_deb_c9069b_

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-jhcq-6wqp-qcfx/GHSA-jhcq-6wqp-qcfx.json"