MEDIUM
CVE-2026-57295
CVSS
5.4
Description
A cross-site request forgery (CSRF) vulnerability in Jenkins EC2 Fleet Plugin 4.2.3.539.v8fedff2a_81c3 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing AWS credentials stored in Jenkins.
Summary dbcve.org
A CSRF vulnerability in Jenkins EC2 Fleet Plugin versions 4.2.3.539.v8fedff2a_81c3 and earlier allows authenticated users to be tricked into connecting to attacker-specified URLs using attacker-specified credentials IDs, potentially exfiltrating AWS credentials stored in Jenkins.
Mitigation
Update EC2 Fleet Plugin to the latest version that includes CSRF protection fixes, or upgrade Jenkins and the plugin to recent versions with proper CSRF token validation.
Weakness (CWE)
CWE-352
Cross-Site Request Forgery (CSRF)
EPSS Score
0.22%
Probability of exploitation in next 30 days
12.9th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.