Impact
The Jenkins Google Chat Notification Plugin, in versions up to 166.ve6b_de280f2e8, fails to establish the correct context during a credentials lookup. As a result, any user who possesses the Item/Configure permission on a given Jenkins item can retrieve credentials that they should not have access to. This flaw effectively exposes sensitive authentication material, enabling an attacker to re‑use or abuse these credentials for unauthorized access to other systems or services that rely on them.
Affected Systems
The vulnerability applies to Jenkins Project’s Google Chat Notification Plugin versions up to and including 166.ve6b_de280f2e8. Any Jenkins instance that includes this plugin within its configuration is potentially impacted.
Risk and Exploitability
Although no EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, the flaw presents a moderate to high risk because it allows credential theft from privileged configuration users. The CVSS score of 4.3 reflects a moderate severity. The attack can be carried out by any attacker who has Item/Configure permissions, which is typically granted to users with a degree of trust within the Jenkins organization. Because the vulnerability does not require external network access or elevated privileges beyond those permissions, it can be exploited internally by malicious or compromised accounts with sufficient Jenkins configuration rights.
OpenCVE Enrichment