CyberRota Analysis
AI-GeneratedThe Horreum Plugin for Jenkins prior to version 0.16.162.v33b_4a_a_b_5f828 is vulnerable due to improper context settings for credential lookups, enabling attackers with Item/Configure permissions to exfiltrate unauthorized credentials to a specified Horreum URL. This could lead to sensitive information exposure, impacting the integrity and confidentiality of the Jenkins environment. Organizations using this plugin should prioritize applying the latest updates to mitigate potential credential leakage risks.
Original NVD Description
Jenkins Horreum Plugin 0.16.162.v33b_4a_a_b_5f828 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to have Jenkins send credentials they are not entitled to use to the administrator-configured Horreum URL.