Impact
A missing permission check in Jenkins Contrast Continuous Application Security Plugin versions 3.11 and earlier enables attackers who possess Overall or Read access in a Jenkins instance to configure the plugin to connect to an arbitrary external URL using an attacker-supplied username, API key, and service key. The flaw is an authorization bypass (CWE‑862) that allows the Jenkins server to initiate outbound connections to a target host specified by the attacker, potentially exfiltrating data or communicating with malicious services. The description provides no evidence of remote code execution; the impact scope is limited to unauthorized external network traffic.
Affected Systems
The vulnerability affects any Jenkins environment that has the Contrast Continuous Application Security Plugin 3.11 or earlier installed. Only installations where a user has Overall or Read permissions and can modify plugin configuration are susceptible. Systems that do not use this plugin or that deny the relevant permissions are not impacted.
Risk and Exploitability
The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, indicating no widespread exploitation has been observed. The CVSS score is 5.4, reflecting moderate severity. Because Jenkins instances with Overall or Read privileges—users that may be numerous—can modify plugin configuration, affected installations can be considered at moderate to high risk. An attacker can cause the Jenkins server to send outbound traffic that may expose internal data or communicate with compromised services.
OpenCVE Enrichment