Boletines de Vulnerabilidades

CVE-2026-57283

   
Software afectado JENKINS
 
A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier allows attackers to instantiate types related to job or system configuration other than Pipeline steps through the Pipeline Snippet Generator.

Link:

https://nvd.nist.gov/vuln/detail/CVE-2026-57283