CyberRota Analysis
AI-GeneratedThe Sauce OnDemand Plugin for Jenkins versions 2.2.0 and earlier lacks proper permission checks, enabling users with Overall/Read permissions to enumerate stored credential IDs. This vulnerability could lead to unauthorized access to sensitive credentials, potentially compromising the security of Jenkins instances. Organizations using affected versions of Jenkins should prioritize remediation to safeguard their credential management practices.
CVE
CVE-2026-70445
Severity
MEDIUM
CVSS
4.3
EPSS
0.17%
Jenkins
Original NVD Description
Missing permission checks in Jenkins Sauce OnDemand Plugin 2.2.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.