-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:job-import-plugin | maven | <= 3.5 | 3.6 |
The commit diff shows these two functions were modified to add Jenkins.get().hasPermission(JOB_IMPORT) checks in version 3.6. Prior to this fix, these HTTP endpoint handlers: 1) doFillCredentialIdItems - directly exposed credential IDs through UI controls 2) doFillJenkinsSitesItems - revealed Jenkins site configurations. Both lacked authorization checks, enabling credential ID enumeration via the plugin's web interface components.
Ongoing coverage of React2Shell