Impact
The Jenkins SCM-Manager Plugin 1.11.1 and earlier lacks a required permission check. An attacker who has the Overall/Read permission can instruct the plugin to connect to an arbitrary URL using an attacker‑specified credential ID that the attacker has obtained by other means. The plugin then uses that credential ID to access the target URL, effectively capturing credentials that are stored in Jenkins. The result is that the attacker can exfiltrate stored credentials and potentially gain further access to the Jenkins environment or downstream systems. The vulnerability is thus an improper access control flaw that can lead to credential theft.
Affected Systems
This issue affects the Jenkins Project's SCM-Manager Plugin versions 1.11.1 and earlier. All Jenkins installations that run this plugin version are potentially exposed. The vulnerability does not affect newer releases of the plugin. The affected product is Jenkins SCM-Manager Plugin, revision ≤ 1.11.1.
Risk and Exploitability
The EPSS score indicates a very low probability of exploitation (<1%) and the vulnerability is not listed in the CISA KEV catalog, so the formal risk metrics are unclear. The CVSS score of 4.2 indicates a moderate risk level. However, because the flaw permits credential leakage without additional privileges, the potential impact is still significant in environments where credentials are critical. The likely attack vector is through the Jenkins web interface or API, where an authorized but read‑only user can trigger the vulnerable behavior.
OpenCVE Enrichment