A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier allows attackers to instantiate types related to job or system configuration other than Pipeline steps through the Pipeline Snippet Generator.

Project Subscriptions

Vendors Products
Jenkins Project Subscribe
Jenkins Pipeline Groovy Libraries Plugin Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 25 Jun 2026 00:15:00 +0000

Type Values Removed Values Added
Title jenkins-pipeline-groovy: Jenkins Pipeline: Groovy Plugin: Cross-site request forgery allows unauthorized configuration changes.
Weaknesses CWE-940
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 24 Jun 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins Project
Jenkins Project jenkins Pipeline Groovy Libraries Plugin
Vendors & Products Jenkins Project
Jenkins Project jenkins Pipeline Groovy Libraries Plugin

Wed, 24 Jun 2026 17:15:00 +0000

Type Values Removed Values Added
Title CSRF Vulnerability in Jenkins Pipeline Groovy Plugin Allows Unauthorized Configuration Changes

Wed, 24 Jun 2026 16:00:00 +0000

Type Values Removed Values Added
Title CSRF Vulnerability in Jenkins Pipeline Groovy Plugin Enables Unauthorized Configuration Changes CSRF Vulnerability in Jenkins Pipeline Groovy Plugin Allows Unauthorized Configuration Changes

Wed, 24 Jun 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 24 Jun 2026 15:00:00 +0000

Type Values Removed Values Added
Title CSRF Vulnerability in Jenkins Pipeline Groovy Plugin Enables Unauthorized Configuration Changes
Weaknesses CWE-352

Wed, 24 Jun 2026 13:45:00 +0000

Type Values Removed Values Added
Description A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier allows attackers to instantiate types related to job or system configuration other than Pipeline steps through the Pipeline Snippet Generator.
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2026-06-24T14:01:20.564Z

Reserved: 2026-06-24T08:41:44.357Z

Link: CVE-2026-57283

cve-icon Vulnrichment

Updated: 2026-06-24T14:01:16.988Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-06-24T13:20:05Z

Links: CVE-2026-57283 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-06-25T03:00:10Z

Weaknesses