CVE-2026-57292
Description
A cross-site request forgery (CSRF) vulnerability in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method.
Summary dbcve.org
The Jenkins Gitee Plugin before version 1288.v18b_deb_c9069b_ contains a CSRF vulnerability that allows unauthenticated attackers to trick an authenticated Jenkins user into making the Jenkins server connect to an attacker-controlled URL using attacker-specified credential IDs. This enables the attacker to potentially exfiltrate sensitive credentials or cause the Jenkins server to interact with malicious external services.
Mitigation
Update the Jenkins Gitee Plugin to version 1288.v18b_deb_c9069b_ or later once a patched version is released, or disable the plugin if not required. Also ensure Jenkins has CSRF protection enabled globally.