Impact
A missing permission check in Jenkins Violation Comments to GitLab Plugin versions 2.62.0 and earlier allows individuals with Overall/Read permission to enumerate the identifiable credential IDs stored within a Jenkins instance. This flaw exposes credential identifiers, representing an information exposure and improper authorization vulnerability, but does not grant execution of code or access to credential secrets by itself.
Affected Systems
Jenkins installations that have Violation Comments to GitLab Plugin 2.62.0 or earlier deployed are affected. Any Jenkins instance in which a user holds Overall/Read permission can exploit the enumeration functionality, making the flaw relevant to all Jenkins users who can read overall configuration.
Risk and Exploitability
The CVSS score of 4.3 reflects a low to moderate severity. No EPSS score is available, and the vulnerability is not catalogued in KEV, indicating no current widespread exploitation. The attack vector is limited to users who already possess Overall/Read authority, implying that the risk to a Jenkins deployment depends largely on how broadly that permission is granted.
OpenCVE Enrichment