-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:aws-credentials | maven | <= 1.28 | 1.28.1 |
The commit diff shows the vulnerable version of doFillCredentialsIdItems lacked the hasPermission check that was added in the patch. This function is used by multiple plugins to populate credential lists in HTTP endpoints. Without authorization checks, it allowed credential ID enumeration by low-privileged users. The direct addition of permission checks in this function in the security fix confirms its vulnerability.
Ongoing coverage of React2Shell