Description
Missing permission checks in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allow attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method.
Published: 2026-06-24
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Missing permission checks in the Jenkins Gitee Plugin version 1288.v18b_deb_c9069b_ and earlier allow an attacker who has Overall/Read access to connect to a URL of the attacker’s choice using a supplied credential ID. The flaw removes the requirement to verify that the user is authorized to initiate such a connection, permitting the Jenkins server to act as a client to arbitrary external services without sufficient controls. This can lead to unintended data flows or external interactions, potentially exposing the environment to malicious services or leaking sensitive data through credential‑based connections. The vulnerability is caused by an access control weakness in the plugin’s handling of external URL requests, leaving the system open to exploitation by any user with read permissions.

Affected Systems

The Jenkins Gitee Plugin, version 1288.v18b_deb_c9069b_ and earlier, is affected. Any Jenkins instance that has this plugin installed and users are granted Overall/Read permissions is at risk. The product is distributed by the Jenkins Project and typically deployed within Jenkins environments as an optional plugin.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate level of risk. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been documented. An attacker who has Overall/Read permissions can leverage the plugin to connect the Jenkins server to any attacker‑specified URL using a credential ID that the attacker has obtained via other means. The exploit requires only the ability to invoke the plugin’s interface or API and does not need elevated network or process privileges, but it demonstrates a missing access‑control weakness that could let the Jenkins instance communicate with malicious external services and potentially exfiltrate data through credential‑based connections.

Generated by OpenCVE AI on June 24, 2026 at 17:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Jenkins Gitee Plugin to a version newer than 1288.v18b_deb_c9069b_ that implements proper permission checks for external connections.
  • If an upgrade cannot be performed immediately, remove the Gitee plugin from the Jenkins instance or disable it for users lacking administrative rights so that only trusted administrators can initiate external requests.
  • Restrict the scope of Overall/Read permissions to only trusted users and enforce least‑privilege principles to limit the number of accounts that can provide credential IDs to the plugin.

Generated by OpenCVE AI on June 24, 2026 at 17:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 24 Jun 2026 18:15:00 +0000

Type Values Removed Values Added
Title Missing Permission Checks Allowing Arbitrary URL Connections in Jenkins Gitee Plugin
Weaknesses CWE-284

Wed, 24 Jun 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 24 Jun 2026 15:30:00 +0000

Type Values Removed Values Added
Title Missing Permission Checks Allowing Arbitrary URL Connections in Jenkins Gitee Plugin
Weaknesses CWE-284

Wed, 24 Jun 2026 13:45:00 +0000

Type Values Removed Values Added
Description Missing permission checks in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allow attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2026-06-24T15:57:40.884Z

Reserved: 2026-06-24T08:41:44.358Z

Link: CVE-2026-57291

cve-icon Vulnrichment

Updated: 2026-06-24T15:06:27.642Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-24T18:00:17Z

Weaknesses