Description
A missing permission check in Jenkins Violation Comments to GitLab Plugin 2.62.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Published: 2026-08-05
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing permission check in Jenkins Violation Comments to GitLab Plugin versions 2.62.0 and earlier allows individuals with Overall/Read permission to enumerate the identifiable credential IDs stored within a Jenkins instance. This flaw exposes credential identifiers, representing an information exposure and improper authorization vulnerability, but does not grant execution of code or access to credential secrets by itself.

Affected Systems

Jenkins installations that have Violation Comments to GitLab Plugin 2.62.0 or earlier deployed are affected. Any Jenkins instance in which a user holds Overall/Read permission can exploit the enumeration functionality, making the flaw relevant to all Jenkins users who can read overall configuration.

Risk and Exploitability

The CVSS score of 4.3 reflects a low to moderate severity. No EPSS score is available, and the vulnerability is not catalogued in KEV, indicating no current widespread exploitation. The attack vector is limited to users who already possess Overall/Read authority, implying that the risk to a Jenkins deployment depends largely on how broadly that permission is granted.

Generated by OpenCVE AI on August 5, 2026 at 23:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a fixed version of the Violation Comments to GitLab Plugin when it becomes available.
  • Restrict the Overall/Read permission to a minimal set of users to limit enumeration capability.
  • Disable or uninstall the plugin if it is not required for your workflow to eliminate the vulnerable path.

Generated by OpenCVE AI on August 5, 2026 at 23:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins Project
Jenkins Project jenkins Violation Comments To Gitlab Plugin
Vendors & Products Jenkins Project
Jenkins Project jenkins Violation Comments To Gitlab Plugin

Wed, 05 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Missing Permission Check Enables Credential Identifier Enumeration in Jenkins GitLab Plugin

Wed, 05 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Title Missing Permission Check Enables Credential ID Enumeration
Weaknesses CWE-200
CWE-284

Wed, 05 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Title Missing Permission Check Enables Credential ID Enumeration
Weaknesses CWE-200
CWE-284
CWE-693
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description A missing permission check in Jenkins Violation Comments to GitLab Plugin 2.62.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
References

Subscriptions

Jenkins Project Jenkins Violation Comments To Gitlab Plugin
cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2026-08-05T19:36:10.869Z

Reserved: 2026-08-04T14:13:20.603Z

Link: CVE-2026-70444

cve-icon Vulnrichment

Updated: 2026-08-05T19:36:03.303Z

cve-icon NVD

Status : Received

Published: 2026-08-05T18:17:14.237

Modified: 2026-08-05T20:17:15.917

Link: CVE-2026-70444

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T10:05:23Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure