-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:lambdatest-automation | maven | < 1.20.10 | 1.20.10 |
The vulnerability describes a missing permission check in an HTTP endpoint used for credential ID enumeration. Jenkins plugins typically implement HTTP endpoints via methods in Java classes using Stapler framework annotations. The most likely candidate is the method responsible for handling credential listing requests, which would normally require Administer permissions but lacked the check in vulnerable versions. The confidence is medium due to lack of direct code/patch references, but aligns with Jenkins plugin architecture patterns and CWE-862 context.
Ongoing coverage of React2Shell