Impact
This is a CWE-639 authorization bypass vulnerability. Jpom through 2.11.12 fails to validate workspace ownership when resolving repositoryId on the /build/branch-list endpoint, allowing authenticated users to access repositories from other workspaces. Attackers can submit repository identifiers from different workspaces to enumerate repository existence, determine repository type, and execute git ls-remote commands using other workspaces' stored credentials. The vulnerability does not provide arbitrary code execution but enables information disclosure and credential misuse.
Affected Systems
The affected product is Jpom by dromara. Any deployment of Jpom up to and including version 2.11.12 is vulnerable. Versions beyond 2.11.12 are presumed fixed, but administrators should verify the repository version and apply the latest release.
Risk and Exploitability
The CVSS score of 5.3 signals moderate severity. The EPSS score of 0.00251 indicates a very low but non‑zero likelihood that attackers will successfully exploit the flaw. The vulnerability is not in the CISA KEV catalog. Because the attacker must be authenticated, the risk is limited to users with legitimate access. However, the flaw permits enumeration of repositories in other workspaces, determination of their types, and execution of git ls-remote commands using the target workspace’s stored credentials, which can leak sensitive data and potentially enable further credential misuse.
OpenCVE Enrichment