CVE-2026-57303: SSRF
Jenkins Assembla Plugin 1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing attackers able to control the responses of the configured Assembla server to extract secrets from the Jenkins controller or perform server-side request forgery.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Jenkins Assembla Pluginto a version that resolves this vulnerability.Fixed in 1.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57303?
CVE-2026-57303 has a risk rating of 47, indicating it is a significant vulnerability.
How does CVE-2026-57303 affect Jenkins Assembla Plugin?
CVE-2026-57303 allows attackers to exploit improperly configured XML parsing, potentially leading to data extraction or server-side request forgery.
How do I fix CVE-2026-57303?
To fix CVE-2026-57303, update the Jenkins Assembla Plugin to version 1.5 or later, which addresses the XML parser configuration.
Who is affected by CVE-2026-57303?
Any organization using Jenkins with the Assembla Plugin version 1.4 or earlier may be affected by CVE-2026-57303.
What type of attacks can CVE-2026-57303 lead to?
CVE-2026-57303 can lead to XML external entity (XXE) attacks, allowing attackers to extract sensitive information or perform server-side request forgery.