CVE-2026-57293: Medium severity Jenkins Gitee Plugin vulnerability
An incorrect permission check in Jenkins Gitee Plugin 1288.v18bdebc9069b and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credentials IDs of credentials stored in Jenkins.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Jenkins Gitee Pluginto a version that resolves this vulnerability.Fixed in 1288.v18b_deb_c9069b_
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57293?
CVE-2026-57293 has a risk rating of 30, indicating a significant security vulnerability.
How do I fix CVE-2026-57293?
To remediate CVE-2026-57293, upgrade your Jenkins Gitee Plugin to version 1288.v19 or later.
What are the impacts of CVE-2026-57293?
CVE-2026-57293 allows attackers with specific permissions to enumerate credentials IDs, potentially compromising sensitive information.
Who is affected by CVE-2026-57293?
CVE-2026-57293 affects any Jenkins installation using Gitee Plugin version 1288.v18b_deb_c9069b_ or earlier.
What should I do if I cannot upgrade to fix CVE-2026-57293?
If an upgrade is not possible, consider restricting access permissions to mitigate the risks associated with CVE-2026-57293.