CyberRota Analysis
AI-GeneratedA missing permission check in the Jenkins Violation Comments to GitLab Plugin (versions 2.62.0 and earlier) allows users with Overall/Read permissions to enumerate credential IDs stored in Jenkins. This vulnerability could lead to unauthorized access to sensitive credential information, potentially compromising the security of integrated systems. Organizations using affected versions of Jenkins and the GitLab plugin should prioritize patching to mitigate the risk of credential exposure.
Original NVD Description
A missing permission check in Jenkins Violation Comments to GitLab Plugin 2.62.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.