CyberRota Analysis
AI-GeneratedThe Parameterized Remote Trigger Plugin in Jenkins versions 3.2.2 and earlier is vulnerable due to a missing permission check, enabling attackers with Overall/Read permissions to enumerate stored credential IDs. This exposure could lead to unauthorized access to sensitive credentials, increasing the risk of further exploitation within the Jenkins environment. Organizations using affected versions of Jenkins should prioritize this vulnerability to safeguard their credential management and overall security posture.
Original NVD Description
A missing permission check in Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.