Impact
Jenkins External Workspace Manager Plugin versions 1.4.1 and earlier fail to perform a suitable permission check when users browse externally‑managed workspaces. Attackers who possess only the permissive Overall/Read role can view the full contents of workspaces that they should not be able to access, exposing potentially sensitive build artifacts or configuration files.
Affected Systems
The vulnerability affects the Jenkins Project’s External Workspace Manager Plugin, specifically versions 1.4.0 and earlier, which perform no permission verification, and version 1.4.1, which implements an improper check. Any Jenkins installation that has this plugin installed at or below 1.4.1 is susceptible to the flaw.
Risk and Exploitability
The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, but the CVSS score of 4.3 signals a moderate severity. The vulnerability arises because any user who has the broad Overall/Read permission can access externally‑managed workspaces through the workspace browser without a proper authorization check. As a result, the attack vector is local to the Jenkins instance; no additional credentials or network traversal are required beyond an existing read role. In environments where the Overall/Read permission is granted to many users and external workspaces contain sensitive artefacts, the risk of unauthorized data disclosure is significant.
OpenCVE Enrichment