Executive brief
The Jenkins Gitee Plugin, which integrates Jenkins with the Gitee code hosting platform, contains a security flaw where it fails to verify user permissions for certain network connections. This allows an attacker with basic 'Read' access to the Jenkins dashboard to force the server to connect to an external web address of their choosing. This could be used to probe internal network services or potentially misuse stored credentials if their IDs are known.
Technical details
The Jenkins Gitee Plugin (version 1288.v18b_deb_c9069b_ and earlier) fails to perform adequate permission checks on an HTTP endpoint used for connection testing or configuration. An attacker with Overall/Read permission can trigger the plugin to initiate an outbound connection to a specified URL. If the attacker has obtained credential IDs through other means, they can also specify these IDs to be used in the connection attempt. This vulnerability is a form of Server-Side Request Forgery (SSRF) resulting from missing authorization. As of the advisory date, the severity is rated as 'info' by the vendor.
Affected products
- Jenkins Project Gitee Plugin 1288.v18b_deb_c9069b_ and earlier
Timeline
- 2026-06-24: disclosed
- 2026-06-24: advisory