Impact
The Multibranch Plugin incorrectly sets the context for credentials lookup during the resolveScm Pipeline step, allowing an attacker with Item/Configure permission on a job to read and capture credentials they are not entitled to. This results in non‑privileged users gaining exposure to sensitive credentials, which can lead to further compromise of downstream systems. The weakness is classified as CWE‑863, reflecting an authorization bypass that permits unauthorized access to protected resources.
Affected Systems
Jenkins Pipeline: Multibranch Plugin versions prior to 841.vec5b_9e1806ec in the Jenkins Project are affected. Any Jenkins instance that uses these plugin versions is vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 3.1, indicating low severity, and an EPSS of less than 1 %, suggesting a low likelihood of exploitation. It is not currently listed in CISA’s KEV catalog. Exploitation requires that the attacker have Item/Configure rights on a job and can run Pipeline steps that invoke resolveScm; the attack surface is therefore limited to trusted or compromised users with job configuration privileges. The impact is credential disclosure only, but the exposed credentials could be used to attack other services or systems.
OpenCVE Enrichment