Impact
The Jenkins Sauce OnDemand Plugin versions 2.2.0 and earlier contain missing permission checks that allow anyone with Overall/Read access to enumerate the identifiers of credentials stored in Jenkins. This enumeration exposes credential IDs, which is an information disclosure vulnerability. No additional evidence is provided that enumeration leads to credential theft or other attacks; the impact is limited to disclosure of IDs.
Affected Systems
The affected product is the Jenkins Sauce OnDemand Plugin version 2.2.0 and all earlier releases. Any Jenkins installation that has this plugin installed and users possessing even basic read privileges is vulnerable. The vulnerability does not affect the core Jenkins engine directly but impacts plugins handling credential storage.
Risk and Exploitability
An attacker with Overall/Read permissions can use the plugin’s API or UI to request credential identifiers, bypassing intended permission checks. The EPSS score of <1% signals a very low exploitation probability, and the issue is not listed in KEV, indicating no known public exploitation yet. The CVSS score of 4.3 reflects the potential for information disclosure via credential ID enumeration. The attack path is straightforward for any user that has read access on the Jenkins instance.
OpenCVE Enrichment