CyberRota Analysis
AI-GeneratedThe SCM-Manager Plugin for Jenkins is vulnerable to a cross-site request forgery (CSRF) flaw that allows attackers to connect to a malicious URL using compromised credentials. This could lead to the unauthorized exposure of sensitive credentials stored within Jenkins. Organizations utilizing affected versions of this plugin should prioritize patching to mitigate the risk of credential theft.
CVE
CVE-2026-70434
Severity
MEDIUM
CVSS
4.2
EPSS
0.09%
Jenkins
Original NVD Description
A cross-site request forgery (CSRF) vulnerability in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.