Impact
The vulnerability allows a malicious actor who controls the content of a Jenkins build log to insert a Develocity build scan link that points to an attacker‑specified URL. The Jenkins Gradle Plugin, when processing the log, connects to this URL and retrieves the Develocity access key that is stored in Jenkins’ global configuration, even though a Develocity server URL has already been configured. This causes the accidental export of a privileged key and therefore a loss of confidentiality for the build environment. The weakness is an Improper Neutralization of Special Elements Used in an Argument, shown in the CWE list.
Affected Systems
Jenkins Gradle Plugin versions 2.19.1252 and prior. Any Jenkins installation that uses these plugin versions and has an active global Develocity configuration is affected.
Risk and Exploitability
The CVSS score of 5.4 reflects moderate severity. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild, and the issue is not listed in the CISA KEV catalog. The likely attack vector is that an adversary must already be able to influence the content that is written to the build log, which could be achieved by injecting malicious code into a build or by exploiting a build‑execution privilege. Once the log contains a malicious link, the vulnerable plugin will reach out and expose the Develocity access key because it does not verify that the target URL matches the configured Develocity server URL.
OpenCVE Enrichment