Impact
Jenkins GitLab Plugin versions through 1.2149.vcfc32c82b_f7f store a GitLab API client in a cache whose key is derived only from the credentials identifier, ignoring the folder context. This design flaw lets an attacker who has Item/Configure permission on a Jenkins item obtain the API token associated with another credentials entry they are not authorized to use. The exposed token permits the attacker to authenticate as the original credential holder and access the victim’s GitLab resources, potentially exposing repositories, secrets and other sensitive data. No arbitrary code execution or denial of service is reported; the core risk is the disclosure of privileged credentials.
Affected Systems
The vulnerability affects the Jenkins Project: Jenkins GitLab Plugin, specifically all releases up to and including 1.2149.vcfc32c82b_f7f. Users deploying older versions of this plugin are susceptible until an update containing the cache key fix is installed.
Risk and Exploitability
With a CVSS score of 5.4 the risk assessment is medium. The EPSS score of less than 1% indicates a low probability that the vulnerability is actively exploited in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to possess Item/Configure rights on a Jenkins project, a permission that should be restricted to administrators or trusted users. Once those rights are attained, the attacker can read the compromised credentials via the Jenkins UI or API.
OpenCVE Enrichment