Impact
Jenkins GitLab Plugin versions 1.9.16 and earlier allow an attacker to overwrite the global GitLab connection configuration through Stapler data binding. This flaw permits the attacker to redirect GitLab API requests to an attacker‑specified URL while retaining the API tokens that administrators have already stored. The underlying weakness stems from inadequate input validation, corresponding to CWE‑471 and CWE‑494.
Affected Systems
All Jenkins installations that use Jenkins GitLab Plugin version 1.9.16 or any earlier release are affected. The vulnerability is confined to the plugin component and does not propagate beyond the Jenkins process. No other vendors or product families are reported to be impacted.
Risk and Exploitability
The CVSS score of 5.4 categorizes this flaw as medium severity. EPSS is not available and the vulnerability is not listed in CISA KEV, indicating no known widespread exploitation at present. The attack requires the ability to submit a configuration request that reaches the Stapler data binding endpoint, which typically means the attacker has access to the Jenkins management UI or API. Based on the description, it is inferred that the attacker can use the preserved API tokens to authenticate to a malicious GitLab instance, potentially exposing repository data or enabling further attacks. Overall, the risk is moderate with a realistic but not immediate threat level.
OpenCVE Enrichment