PT-2026-51793 · Jenkins · Pipeline: Groovy Plugin
CVE-2026-57283
·
Published
2026-06-24
·
Updated
2026-06-26
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Pipeline: Groovy Plugin versions prior to 4331.v9d06ed4658ff
Description
A cross-site request forgery (CSRF) issue exists in the Pipeline Snippet Generator. This flaw allows attackers to instantiate types related to system configuration or jobs that are not intended to be Pipeline steps. CSRF is a technique where an attacker tricks a victim into performing actions they did not intend to do on a different website.
Recommendations
Update Jenkins Pipeline: Groovy Plugin to a version later than 4331.v9d06ed4658ff.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pipeline: Groovy Plugin