Lucene search

K
osvGoogleOSV:GHSA-5PHJ-QV74-PV4W
HistoryMay 18, 2022 - 12:00 a.m.

Missing permission check in Jenkins GitLab Plugin

2022-05-1800:00:40
Google
osv.dev
8

0.001 Low

EPSS

Percentile

28.4%

Jenkins GitLab Plugin 1.5.31 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. An enumeration of credentials IDs in GitLab Plugin 1.5.32 requires the appropriate permissions.

0.001 Low

EPSS

Percentile

28.4%

Related for OSV:GHSA-5PHJ-QV74-PV4W