Impact
A missing permission check in Jenkins HCL AppScan Plugin versions 1.8.3 and earlier allows an attacker who has Overall/Read access to enumerate the IDs of credentials stored in Jenkins. The vulnerability description indicates that the plugin exposes credential identifiers to users lacking proper permission protection. Based on the description, it is inferred that obtaining these credential IDs could aid an attacker in further credential theft or compromise operations within the Jenkins environment.
Affected Systems
The affected product is the Jenkins HCL AppScan Plugin for Jenkins, specifically versions 1.8.3 and any earlier release. Users running these versions are at risk of exposing credential identifiers to unauthorized individuals.
Risk and Exploitability
The EPSS score is less than 1% and the vulnerability is not listed in CISA KEV, indicating no publicly documented exploits as of the data provided. The CVSS score of 4.3 indicates moderate severity. The likely attack vector is any user who can log in with Overall/Read privileges. Because the plugin performs the enumeration without additional checks, the risk is elevated in environments where read permissions are broadly granted. Organizations should treat this as a moderate-impact information-disclosure vulnerability and prioritize remediation.
OpenCVE Enrichment