Permission Check Flaw in Jenkins OpenTelemetry Plugin by Jenkins
CVE-2025-58460

4.2MEDIUM

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
3 September 2025

What is CVE-2025-58460?

A security flaw exists in the Jenkins OpenTelemetry Plugin that lacks a necessary permission check. This vulnerability enables attackers who possess Overall/Read permission to exploit the system by connecting to a maliciously specified URL. Utilizing attacker-controlled credentials IDs, they can capture sensitive credentials stored within Jenkins, potentially compromising the entire system. Users are advised to update to the latest version of the plugin to mitigate this risk.

Affected Version(s)

Jenkins OpenTelemetry Plugin 0 <= 3.1543.v8446b_92b_cd64

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.