Permission Check Flaw in Jenkins GitLab Plugin Allows Credential Enumeration
CVE-2025-24397
4.3MEDIUM
What is CVE-2025-24397?
A security vulnerability exists in the Jenkins GitLab Plugin, specifically in versions up to 1.9.6, due to an improper permission check. This flaw enables attackers who possess global Item/Configure permissions, but do not have permissions on specific jobs, to enumerate sensitive credential IDs associated with GitLab API tokens and Secret text credentials stored within Jenkins. This could potentially compromise the confidentiality of sensitive information, allowing unauthorized access and manipulation.
Affected Version(s)
Jenkins GitLab Plugin 0 <= 1.9.6