PT-2026-51813 · Jenkins · Assembla Plugin

·

CVE-2026-57303

·

Published

2026-06-24

·

Updated

2026-06-25

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Assembla Plugin versions prior to 1.5
Description The XML parser is not configured to prevent XML external entity (XXE) attacks. This allows attackers who can control the responses from the configured Assembla server to extract secrets from the Jenkins controller or perform server-side request forgery (SSRF), which is a technique used to induce the server to make requests to an unintended location.
Recommendations Update Jenkins Assembla Plugin to version 1.5 or later.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57303

Affected Products

Assembla Plugin