MEDIUM

CVE-2026-57295

Jenkins Ec2 Fleet 2026-06-24 CVSS v3.1
CVSS
5.4

Description

A cross-site request forgery (CSRF) vulnerability in Jenkins EC2 Fleet Plugin 4.2.3.539.v8fedff2a_81c3 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing AWS credentials stored in Jenkins.

Summary dbcve.org

A CSRF vulnerability in Jenkins EC2 Fleet Plugin versions 4.2.3.539.v8fedff2a_81c3 and earlier allows authenticated users to be tricked into connecting to attacker-specified URLs using attacker-specified credentials IDs, potentially exfiltrating AWS credentials stored in Jenkins.

Mitigation

Update EC2 Fleet Plugin to the latest version that includes CSRF protection fixes, or upgrade Jenkins and the plugin to recent versions with proper CSRF token validation.

Weakness (CWE)

CWE-352 Cross-Site Request Forgery (CSRF)

EPSS Score

0.22%
Probability of exploitation in next 30 days
12.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE