Vulnerability GHSA-wg26-8wmj-cf9p

Medium Risk
MEDIUM RISK
CVSS Score: 4.3
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
5 months ago
April 29, 2026 at 03:30 PM UTC
Jenkins GitHub Branch Source Plugin: Missing permissions check allows attackers to perform a connection test
1.0.0 - 1.10.1 and 2.4.5 - 2.4.6 and 2.6.0 and 2.8.0 and 2.8.2 - 2.8.3 and 2.9.9
1.0.0 - 1.10.1 and 2.4.5 - 2.4.6 and 2.6.0 and 2.8.0 and 2.8.2 - 2.8.3 and 2.9.9

Summary

Jenkins GitHub Branch Source Plugin: Missing permissions check allows attackers to perform a connection test

Details

Jenkins GitHub Branch Source Plugin versions 1967.vdea_d580c1a_b_a_ and earlier do not perform a permission check in a method implementing form validation.

This allows attackers with Overall/Read permission to connect to an attacker-specified URL with attacker-specified GitHub App credentials.

GitHub Branch Source Plugin 1967.1969.v205fd594c821 requires Overall/Manage permission to perform the connection test.

Timeline

Published
5 months ago
April 29, 2026 at 03:30 PM UTC
Last Modified
4 months ago
May 06, 2026 at 11:11 PM UTC