CVE-2026-57285 PUBLISHED

Assigner: jenkins
Reserved: 24.06.2026 Published: 24.06.2026 Updated: 24.06.2026

A missing permission check in Jenkins GitHub Branch Source Plugin 1967.1969.v205fd594c821 and earlier allows attackers with Overall/Read permission to obtain the URLs of GitHub Enterprise servers configured in the global plugin configuration.

Product Status

Vendor Jenkins Project
Product Jenkins GitHub Branch Source Plugin
Versions Default: unaffected
  • affected from 0 to 1967.1969.v205fd594c821 (incl.)

References