Impact
Missing permission checks in Jenkins AWS CodeBuild Plugin version 0.59 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs stored in Jenkins. This disclosure enables an adversary to gather identifiers of stored credentials without direct access to the credential values, potentially facilitating further credential‑based attacks if additional privileges are obtained.
Affected Systems
Affected systems include Jenkins Project's Jenkins AWS CodeBuild Plugin version 0.59 and earlier. Users of Jenkins deployments that have installed this plugin are potentially exposed.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and no EPSS score is available. The vulnerability is not listed in CISA KEV, indicating no current evidence of exploitation. However, the ability to enumerate credential IDs with read access poses a moderate risk, as an attacker who already has overall or read permissions could use the enumeration information to target specific credentials or amplify an existing compromise. The attack vector is inferred to be local or network based within the Jenkins environment, requiring only read rights, which many users possess.
OpenCVE Enrichment