Missing Authorization Affecting org.jenkins-ci.plugins:ec2-fleet package, versions [,4.2.3.540.va_6eedb_7b_c112)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.16% (6th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGJENKINSCIPLUGINS-17756764
  • published1 Jul 2026
  • disclosed25 Jun 2026
  • creditdyingman1 (https://github.com/dyingman1, redpoc Offensive Security Team)

Introduced: 25 Jun 2026

CVE-2026-57294  (opens in a new tab)
CWE-862  (opens in a new tab)

How to fix?

Upgrade org.jenkins-ci.plugins:ec2-fleet to version 4.2.3.540.va_6eedb_7b_c112 or higher.

Overview

Affected versions of this package are vulnerable to Missing Authorization due to not performing permission checks in several HTTP endpoints that used to validate cloud configurations. This allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing AWS credentials stored in Jenkins. Additionally, these HTTP endpoints do not require POST requests, resulting in a cross-site request forgery (CSRF) vulnerability.

CVSS Base Scores

version 4.0
version 3.1