Description
A cross-site request forgery (CSRF) vulnerability in Jenkins Assembla Plugin 1.4 and earlier allows attackers to connect to an attacker-specified URL using an attacker-specified username and password.
Published: 2026-06-24
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a cross‑site request forgery that lets an attacker make the Jenkins Assembla Plugin 1.4 and earlier reach an arbitrary URL chosen by the attacker, supplying any username and password the attacker wishes to use. The result is that the Jenkins server can act as a client to external services on behalf of the attacker, potentially authorizing against those services with credentials that the attacker controls. The weakness is defined as CWE‑352.

Affected Systems

The flaw affects Jenkins Project’s Assembla Plugin version 1.4 and all earlier releases. Any Jenkins installation that has this plugin installed at these versions is potentially vulnerable. The exact version range is 1.4 and lower; later releases are unknown to be unaffected.

Risk and Exploitability

The CVSS score for this issue is 5.4, indicating a moderate severity. An EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited known exploitation at this time. Because the flaw is a CSRF attack that requires a forged request from a user already authenticated to the Jenkins instance, the risk depends on the presence of a privileged user session that can be co‑erased. If such a session exists, the attacker may be able to force the server to connect to arbitrary endpoints with supplied credentials, creating a covert channel for external communication. Overall, the exploitation likelihood is moderate given the need for a valid user session and the absence of known public exploits.

Generated by OpenCVE AI on June 24, 2026 at 15:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a patched version of the Assembla Plugin (v1.5 or later).
  • If the plugin is not required, disable or uninstall it from the Jenkins instance.
  • Ensure Jenkins’ global CSRF protection is enabled so that all plugins require valid CSRF tokens.

Generated by OpenCVE AI on June 24, 2026 at 15:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 24 Jun 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins Project
Jenkins Project jenkins Assembla Plugin
Vendors & Products Jenkins Project
Jenkins Project jenkins Assembla Plugin

Wed, 24 Jun 2026 15:00:00 +0000

Type Values Removed Values Added
Title CSRF Enables External Connections via Jenkins Assembla Plugin

Wed, 24 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-352
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 24 Jun 2026 13:45:00 +0000

Type Values Removed Values Added
Description A cross-site request forgery (CSRF) vulnerability in Jenkins Assembla Plugin 1.4 and earlier allows attackers to connect to an attacker-specified URL using an attacker-specified username and password.
References

Subscriptions

Jenkins Project Jenkins Assembla Plugin
cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2026-06-24T14:01:45.496Z

Reserved: 2026-06-24T08:41:44.359Z

Link: CVE-2026-57305

cve-icon Vulnrichment

Updated: 2026-06-24T14:01:01.909Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-24T20:40:51Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)