CVE-2026-57297: Medium severity Contrast Security Contrast Continuous Application Security Plugin vulnerability
A missing permission check in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using an attacker-specified username, API key, and service key.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57297?
CVE-2026-57297 has a risk score of 40, indicating a significant potential impact.
How do I fix CVE-2026-57297?
To fix CVE-2026-57297, update the Jenkins Contrast Continuous Application Security Plugin to version 3.12 or later.
What are the potential impacts of CVE-2026-57297?
CVE-2026-57297 allows unauthorized users to connect to arbitrary URLs, potentially leading to data exposure or unauthorized access.
Who is affected by CVE-2026-57297?
CVE-2026-57297 affects users of Jenkins Contrast Continuous Application Security Plugin versions 3.11 and earlier.
Is there any workaround for CVE-2026-57297?
There are no specific workarounds for CVE-2026-57297; the best action is to update the plugin to mitigate the vulnerability.