Impact
The Jenkins Horreum Plugin version 0.16.162.v33b_4a_a_b_5f828 and earlier fails to set the correct context for credential lookup, allowing an attacker with Item/Configure permission to cause Jenkins to send credentials they are not entitled to use to an administrator‑configured Horreum URL. This flaw results in the unintended disclosure of secrets, which is a form of improper access control and information exposure (CWE‑269). The CVSS score of 4.3 indicates a medium severity vulnerability that threatens the confidentiality of stored credentials.
Affected Systems
The affected product is the Jenkins Horreum Plugin distributed by the Jenkins Project. Versions 0.16.162.v33b_4a_a_b_5f828 and earlier are impacted. Administrators should verify the exact version in use and plan to upgrade to a fixed release.
Risk and Exploitability
The CVSS score of 4.3 combined with the lack of EPSS data suggests that the flaw can be exploited by any user who has been granted Item/Configure rights. Those rights commonly allow changes to build configuration, so an insider or a compromised user could trigger the credential leak to a malicious external endpoint. The vulnerability is not listed in the CISA KEV catalog, which indicates no known widespread exploitation at this time, but the risk to confidentiality remains significant, especially in environments where credential reuse or external integrations are common.
OpenCVE Enrichment