CVE-2026-57295: CSRF
A cross-site request forgery (CSRF) vulnerability in Jenkins EC2 Fleet Plugin 4.2.3.539.v8fedff2a81c3 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing AWS credentials stored in Jenkins.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57295?
The severity of CVE-2026-57295 is rated at 60.
How do I fix CVE-2026-57295?
To fix CVE-2026-57295, update the Jenkins EC2 Fleet Plugin to version 4.2.3.540.v8fedff2a_81c3 or later.
What type of vulnerability is CVE-2026-57295?
CVE-2026-57295 is a cross-site request forgery (CSRF) vulnerability.
What does CVE-2026-57295 allow attackers to do?
CVE-2026-57295 allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs, potentially capturing AWS credentials.
Which software is affected by CVE-2026-57295?
The affected software is the Jenkins EC2 Fleet Plugin, specifically versions 4.2.3.539.v8fedff2a_81c3 and earlier.