Impact
Missing permission checks in the Jenkins CodeSonar Plugin versions 3.6.0 and earlier allow users who possess Overall/Read permission to enumerate the credential IDs stored in Jenkins. The vulnerability enables a disclosure of sensitive information without requiring additional exploits or code execution. While it does not directly reveal the credential values, obtaining credential identifiers can facilitate further attacks if those identifiers are linked to credentials in other systems or if an attacker subsequently gains higher privileges.
Affected Systems
The Jenkins Project Jenkins CodeSonar Plugin up to and including version 3.6.0 is affected. Any installation of the plugin that has not been updated beyond this version is vulnerable. The issue manifests when the plugin is used to scan or analyze code with Jenkins’ credentials configuration.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. The exploit does not leverage remote code execution and requires only the ability to access the Jenkins interface with overall or read permissions. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the attack vector requires authenticated access, the attack surface is limited to users who already have some level of access to Jenkins. The risk is moderate, focused on potential credential enumeration rather than immediate compromise of credential secrets. The lack of a publicly known exploit further mitigates immediate threat.
OpenCVE Enrichment