{"id":"GHSA-w794-rwp2-jc9m","summary":"Jenkins Gitee Plugin has a cross-site request forgery vulnerability","details":"Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier does not perform permission checks in several HTTP endpoints implementing form validation for its global configuration.\n\nThis allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.\n\nAdditionally, these HTTP endpoints do not require POST requests, resulting in a cross-site request forgery (CSRF) vulnerability.\n\nGitee Plugin 1292.v2559f2f3f2c0 requires the appropriate permissions in the affected HTTP endpoints, and requires POST requests.","aliases":["CVE-2026-57292"],"modified":"2026-09-25T19:15:04.588169432Z","published":"2026-06-24T15:31:47Z","database_specific":{"cwe_ids":["CWE-352"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-09-25T19:04:10Z","nvd_published_at":"2026-06-24T14:17:35Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-57292"},{"type":"WEB","url":"https://github.com/jenkinsci/gitee-plugin/pull/199"},{"type":"WEB","url":"https://github.com/jenkinsci/gitee-plugin/commit/2559f2f3f2c02659d9abe5ab3d66c13cef9278dc"},{"type":"PACKAGE","url":"https://github.com/jenkinsci/gitee-plugin"},{"type":"WEB","url":"https://github.com/jenkinsci/gitee-plugin/releases/tag/1292.v2559f2f3f2c0"},{"type":"WEB","url":"https://www.jenkins.io/security/advisory/2026-06-24/#SECURITY-3762%20(1)"}],"affected":[{"package":{"name":"org.jenkins-ci.plugins:gitee","ecosystem":"Maven","purl":"pkg:maven/org.jenkins-ci.plugins/gitee"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1292.v2559f2f3f2c0"}]}],"versions":["1.0.11","1.0.12","1.0.13","1.0.14","1.1.1","1.1.10","1.1.11","1.1.12","1.1.13","1.1.14","1.1.15","1.1.2","1.1.3","1.1.4","1.1.5","1.1.7","1.1.8","1.1.9","1.2.1","1.2.2","1.2.3","1.2.4","1.2.5","1.2.6","1.2.7","1164.v92b_911c15f28","1165.vd01443918414","1170.v3d4640b_34233","1189.v6cb_10c9d63b_8","1190.v317d91b_3a_4e2","1195.ve7a_e26d4a_898","1197.v2a_b_30a_0982b_7","1198.vf35a_c423421e","1201.vc0f481dff802","1204.v4635f4272c96","1224.v843da_c08c504","1232.v1f6eca_6f587e","1245.vb_39c7f51d6b_2","1246.va_96d8b_79c02f","1247.v3cf071d5ff46","1250.vef5eeda_60678","1251.vb_37e0d6e1b_e7","1252.v891b_4e5f0303","1253.vb_5564dd738c8","1255.v1b_42e96a_378b_","1256.ve06b_0354a_c88","1257.v94e12c8783d7","1258.v1a_3914c28c90","1259.va_7b_c7a_46a_79d","1260.v88b_b_167e8cb_7","1261.v9f3fef7e413b_","1265.va_1ef8dc4329f","1266.v5743e3349d54","1271.vf8493ca_07721","1272.v583461cd985b_","1277.v4988370637e3","1278.v35c10a_5844c0","1282.vcb_38e525f3c5","1288.v18b_deb_c9069b_"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-w794-rwp2-jc9m/GHSA-w794-rwp2-jc9m.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"}]}