PT-2026-51803 · Jenkins · Jenkins Git Plugin
Published
2026-06-24
·
Updated
2026-06-24
·
CVE-2026-57293
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
An incorrect permission check in Jenkins Gitee Plugin 1288.v18b deb c9069b and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credentials IDs of credentials stored in Jenkins.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins Git Plugin