Back to CVE List

CVE-2026-57297

Vulnerability Description

A missing permission check in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using an attacker-specified username, API key, and service key.

Vulnerability Details

Published Date
Last Modified
Source
NVD
Vendor
Jenkins Project
Product
Jenkins Contrast Continuous Application Security Plugin

External References

Discussion (0)

Add Comment

No comments yet. Be the first!