Jenkins GitHub Branch Source Plugin: Missing permissions check allows attackers to perform a connection test
Moderate severity
GitHub Reviewed
Published
Apr 29, 2026
to the GitHub Advisory Database
•
Updated May 6, 2026
Package
Affected versions
< 1967.1969.v205fd594c821
Patched versions
1967.1969.v205fd594c821
Description
Published by the National Vulnerability Database
Apr 29, 2026
Published to the GitHub Advisory Database
Apr 29, 2026
Reviewed
May 6, 2026
Last updated
May 6, 2026
Jenkins GitHub Branch Source Plugin versions 1967.vdea_d580c1a_b_a_ and earlier do not perform a permission check in a method implementing form validation.
This allows attackers with Overall/Read permission to connect to an attacker-specified URL with attacker-specified GitHub App credentials.
GitHub Branch Source Plugin 1967.1969.v205fd594c821 requires Overall/Manage permission to perform the connection test.
References