{"id":"CVE-2026-57292","aliases":["GHSA-w794-rwp2-jc9m"],"title":"Jenkins Gitee Plugin has a cross-site request forgery vulnerability","summary":"Jenkins Gitee Plugin has a cross-site request forgery vulnerability","severity":"medium","cvss":5.4,"cwe":["CWE-352"],"vendor":"jenkins-ci","product":"org.jenkins-ci.plugins:gitee","ecosystem":"maven","affected":["org.jenkins-ci.plugins:gitee < 1292.v2559f2f3f2c0"],"patched":["org.jenkins-ci.plugins:gitee 1292.v2559f2f3f2c0"],"published":"2026-06-24","updated":"2026-09-25","sourceUpdated":"2026-09-25T19:04:11Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-w794-rwp2-jc9m","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-57292"},{"url":"https://www.jenkins.io/security/advisory/2026-06-24/#SECURITY-3762%20(1)"},{"url":"https://github.com/jenkinsci/gitee-plugin/pull/199"},{"url":"https://github.com/jenkinsci/gitee-plugin/commit/2559f2f3f2c02659d9abe5ab3d66c13cef9278dc"},{"url":"https://github.com/jenkinsci/gitee-plugin/releases/tag/1292.v2559f2f3f2c0"},{"url":"https://github.com/advisories/GHSA-w794-rwp2-jc9m"}],"tags":["ghsa","maven"],"epss":0.00136,"epssPercentile":0.02463,"ingestedAt":"2026-09-25T19:15:38.960Z","slug":"CVE-2026-57292","body":"## Overview\n\nJenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier does not perform permission checks in several HTTP endpoints implementing form validation for its global configuration.\n\nThis allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.\n\nAdditionally, these HTTP endpoints do not require POST requests, resulting in a cross-site request forgery (CSRF) vulnerability.\n\nGitee Plugin 1292.v2559f2f3f2c0 requires the appropriate permissions in the affected HTTP endpoints, and requires POST requests.\n\n## Affected packages\n\n- `org.jenkins-ci.plugins:gitee < 1292.v2559f2f3f2c0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `org.jenkins-ci.plugins:gitee 1292.v2559f2f3f2c0`","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}