Database/Control plane, storage & DevOps
Jenkins Stapler: CSRF crumb embedded in generated JavaScript leaks to same-site attackers
Impact
An HTTP endpoint that serves dynamically generated JavaScript embeds the user's CSRF crumb as a string literal, so anything hosted on the same site as Jenkins can read it and then act as that user. Jenkins deployments commonly serve user-controlled content from the same origin - Allure and other report publishers, workspace artifact browsing - which is precisely the position this needs. If the targeted user is a Jenkins administrator, the attacker gets to perform administrative actions against a controller that holds cluster and registry credentials for the GPU fleet. Affects Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (except 2088.2093.vd7c3e58008a_6), shipped in Jenkins 2.447 through 2.579, LTS 2.452.1 through 2.568.2.
Who can reach it
An attacker who controls a page hosted on the same site as Jenkins, plus a logged-in Jenkins user who visits it. No Jenkins account required for the attacker if same-site content can be planted through artifacts or published reports.
What to do
Upgrade Jenkins to a release shipping fixed Stapler and restart the controller; the record does not name the fixed version. Where practical, serve build artifacts and published reports from a separate origin so same-site content cannot reach the crumb. Short CI outage, no fleet impact.
References
Related entries
- Jenkins: transient fields cannot be excluded from deserialization of submitted configurationCVE-2026-84650 · Jenkins controller (XStream configuration deserialization, transient fields)High
- Jenkins SAML Plugin: IdP metadata file overwritable via data binding, allowing login as any userCVE-2026-84668 · Jenkins SAML Plugin (IdP metadata file, Stapler data binding)High
- Jenkins Allure Plugin: path traversal lets Item/Read users read arbitrary controller filesCVE-2026-84669 · Jenkins Allure Plugin (report path handling)High
- Jenkins Performance Plugin: unsafe deserialization of cached reports gives Item/Configure users RCECVE-2026-84670 · Jenkins Performance Plugin (cached performance report deserialization)High
- Jenkins File Parameter Plugin: arbitrary file write on the controller via data binding leads to RCECVE-2026-84671 · Jenkins File Parameter Plugin (Stapler data binding, file write path)High
- Jenkins Entra ID plugin: a colliding Entra group display name inherits a privileged group's permissionsCVE-2026-84672 · Jenkins Microsoft Entra ID plugin (group authorization by display name)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.