Skip to content

Commit 3d50b50

Browse files
1 parent 24d5f36 commit 3d50b50

4 files changed

Lines changed: 130 additions & 72 deletions

File tree

Lines changed: 61 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,61 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-5qh3-hxx9-w26p",
4+
"modified": "2026-09-25T19:20:00Z",
5+
"published": "2026-06-24T15:31:48Z",
6+
"aliases": [
7+
"CVE-2026-57301"
8+
],
9+
"summary": "Jenkins OWASP ZAP Plugin: Builds executed on the Jenkins controller can lead to RCE",
10+
"details": "Jenkins OWASP ZAP Plugin 1.0.7 and earlier does not support distributed builds, causing the file operations and build process of its \"Automatically build ZAP\" feature to be performed on the Jenkins controller rather than on the agent the build is assigned to.\n\nThis allows attackers with Item/Configure permission to configure the feature to build an attacker-controlled project, executing arbitrary code on the Jenkins controller and bypassing any restriction confining the build to a specific agent.\n\nAs of publication of this advisory, there is no fix.",
11+
"severity": [
12+
{
13+
"type": "CVSS_V3",
14+
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
15+
}
16+
],
17+
"affected": [
18+
{
19+
"package": {
20+
"ecosystem": "Maven",
21+
"name": "org.jenkins-ci.plugins:zapper"
22+
},
23+
"ranges": [
24+
{
25+
"type": "ECOSYSTEM",
26+
"events": [
27+
{
28+
"introduced": "0"
29+
},
30+
{
31+
"last_affected": "1.0.7"
32+
}
33+
]
34+
}
35+
]
36+
}
37+
],
38+
"references": [
39+
{
40+
"type": "ADVISORY",
41+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-57301"
42+
},
43+
{
44+
"type": "PACKAGE",
45+
"url": "https://github.com/adedayo/zapper"
46+
},
47+
{
48+
"type": "WEB",
49+
"url": "https://www.jenkins.io/security/advisory/2026-06-24/#SECURITY-3649"
50+
}
51+
],
52+
"database_specific": {
53+
"cwe_ids": [
54+
"CWE-610"
55+
],
56+
"severity": "HIGH",
57+
"github_reviewed": true,
58+
"github_reviewed_at": "2026-09-25T19:20:00Z",
59+
"nvd_published_at": "2026-06-24T14:17:36Z"
60+
}
61+
}
Lines changed: 69 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,69 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-mpff-xhg4-vr45",
4+
"modified": "2026-09-25T19:19:00Z",
5+
"published": "2026-06-24T15:31:48Z",
6+
"aliases": [
7+
"CVE-2026-57300"
8+
],
9+
"summary": "Jenkins MCP Server Plugin missing a permission check",
10+
"details": "Jenkins MCP Server Plugin 0.177.v629fdb_2557fe and earlier does not perform a permission check in the getReplayScripts MCP tool that returns the replay script of a Pipeline build.\n\nThis allows attackers with Item/Read permission to obtain the Pipeline script of jobs.\n\nMCP Server Plugin 0.178.vffe5a_e770f3b_ requires Item/Extended Read permission to return the replay script of a Pipeline build through the getReplayScripts MCP tool.",
11+
"severity": [
12+
{
13+
"type": "CVSS_V3",
14+
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
15+
}
16+
],
17+
"affected": [
18+
{
19+
"package": {
20+
"ecosystem": "Maven",
21+
"name": "io.jenkins.plugins:mcp-server"
22+
},
23+
"ranges": [
24+
{
25+
"type": "ECOSYSTEM",
26+
"events": [
27+
{
28+
"introduced": "0"
29+
},
30+
{
31+
"fixed": "0.178.vffe5a"
32+
}
33+
]
34+
}
35+
]
36+
}
37+
],
38+
"references": [
39+
{
40+
"type": "ADVISORY",
41+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-57300"
42+
},
43+
{
44+
"type": "WEB",
45+
"url": "https://github.com/jenkinsci/mcp-server-plugin/commit/ffe5ae770f3bd7e88c99aea3018263af0b2f9cc4"
46+
},
47+
{
48+
"type": "PACKAGE",
49+
"url": "https://github.com/jenkinsci/mcp-server-plugin"
50+
},
51+
{
52+
"type": "WEB",
53+
"url": "https://github.com/jenkinsci/mcp-server-plugin/releases/tag/0.178.vffe5a_e770f3b_"
54+
},
55+
{
56+
"type": "WEB",
57+
"url": "https://www.jenkins.io/security/advisory/2026-06-24/#SECURITY-3759"
58+
}
59+
],
60+
"database_specific": {
61+
"cwe_ids": [
62+
"CWE-862"
63+
],
64+
"severity": "MODERATE",
65+
"github_reviewed": true,
66+
"github_reviewed_at": "2026-09-25T19:18:59Z",
67+
"nvd_published_at": "2026-06-24T14:17:36Z"
68+
}
69+
}

‎advisories/unreviewed/2026/06/GHSA-5qh3-hxx9-w26p/GHSA-5qh3-hxx9-w26p.json‎

Lines changed: 0 additions & 36 deletions
This file was deleted.

‎advisories/unreviewed/2026/06/GHSA-mpff-xhg4-vr45/GHSA-mpff-xhg4-vr45.json‎

Lines changed: 0 additions & 36 deletions
This file was deleted.

0 commit comments

Comments
 (0)