PT-2026-51793 · Jenkins · Pipeline: Groovy Plugin

CVE-2026-57283

·

Published

2026-06-24

·

Updated

2026-06-26

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Pipeline: Groovy Plugin versions prior to 4331.v9d06ed4658ff
Description A cross-site request forgery (CSRF) issue exists in the Pipeline Snippet Generator. This flaw allows attackers to instantiate types related to system configuration or jobs that are not intended to be Pipeline steps. CSRF is a technique where an attacker tricks a victim into performing actions they did not intend to do on a different website.
Recommendations Update Jenkins Pipeline: Groovy Plugin to a version later than 4331.v9d06ed4658ff.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57283

Affected Products

Pipeline: Groovy Plugin