GHSA-w794-rwp2-jc9m

Suggest an improvement
Source
https://github.com/advisories/GHSA-w794-rwp2-jc9m
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-w794-rwp2-jc9m/GHSA-w794-rwp2-jc9m.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-w794-rwp2-jc9m
Aliases
  • CVE-2026-57292
Published
2026-06-24T15:31:47Z
Modified
2026-09-25T19:15:04Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
Jenkins Gitee Plugin has a cross-site request forgery vulnerability
Details

Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier does not perform permission checks in several HTTP endpoints implementing form validation for its global configuration.

This allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

Additionally, these HTTP endpoints do not require POST requests, resulting in a cross-site request forgery (CSRF) vulnerability.

Gitee Plugin 1292.v2559f2f3f2c0 requires the appropriate permissions in the affected HTTP endpoints, and requires POST requests.

Database specific
{
    "cwe_ids":  [
        "CWE-352"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-09-25T19:04:10Z",
    "nvd_published_at":  "2026-06-24T14:17:35Z",
    "severity":  "MODERATE"
}
References

Affected packages

Maven / org.jenkins-ci.plugins:gitee

Package

Name
org.jenkins-ci.plugins:gitee
View open source insights on deps.dev
Purl
pkg:maven/org.jenkins-ci.plugins/gitee

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1292.v2559f2f3f2c0

Affected versions

1.*
1.0.11
1.0.12
1.0.13
1.0.14
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.7
1.1.8
1.1.9
1.1.10
1.1.11
1.1.12
1.1.13
1.1.14
1.1.15
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1164.*
1164.v92b_911c15f28
1165.*
1165.vd01443918414
1170.*
1170.v3d4640b_34233
1189.*
1189.v6cb_10c9d63b_8
1190.*
1190.v317d91b_3a_4e2
1195.*
1195.ve7a_e26d4a_898
1197.*
1197.v2a_b_30a_0982b_7
1198.*
1198.vf35a_c423421e
1201.*
1201.vc0f481dff802
1204.*
1204.v4635f4272c96
1224.*
1224.v843da_c08c504
1232.*
1232.v1f6eca_6f587e
1245.*
1245.vb_39c7f51d6b_2
1246.*
1246.va_96d8b_79c02f
1247.*
1247.v3cf071d5ff46
1250.*
1250.vef5eeda_60678
1251.*
1251.vb_37e0d6e1b_e7
1252.*
1252.v891b_4e5f0303
1253.*
1253.vb_5564dd738c8
1255.*
1255.v1b_42e96a_378b_
1256.*
1256.ve06b_0354a_c88
1257.*
1257.v94e12c8783d7
1258.*
1258.v1a_3914c28c90
1259.*
1259.va_7b_c7a_46a_79d
1260.*
1260.v88b_b_167e8cb_7
1261.*
1261.v9f3fef7e413b_
1265.*
1265.va_1ef8dc4329f
1266.*
1266.v5743e3349d54
1271.*
1271.vf8493ca_07721
1272.*
1272.v583461cd985b_
1277.*
1277.v4988370637e3
1278.*
1278.v35c10a_5844c0
1282.*
1282.vcb_38e525f3c5
1288.*
1288.v18b_deb_c9069b_

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-w794-rwp2-jc9m/GHSA-w794-rwp2-jc9m.json"