CyberRota Analysis
AI-GeneratedThe SCM-Manager Plugin in Jenkins versions 1.11.1 and earlier lacks a necessary permission check, enabling users with Overall/Read permissions to connect to arbitrary URLs with attacker-specified credentials. This vulnerability can lead to the exposure of sensitive credentials stored within Jenkins, posing a significant risk to the integrity of the CI/CD pipeline. Organizations using affected versions of Jenkins should prioritize remediation to safeguard against potential credential theft and unauthorized access.
Original NVD Description
A missing permission check in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.