CVE-2025-24397 describes an incorrect permission check in Jenkins GitLab Plugin versions 1.9.6 and earlier. This vulnerability allows authenticated attackers with global Item/Configure permissions, even without specific job configuration rights, to enumerate credential IDs for GitLab API tokens and Secret text credentials stored within Jenkins. Rated as Medium severity (CVSS 4.3), the attack requires low privileges and has a low impact on confidentiality, with no integrity or availability impact. Currently, there is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.9.6CPE matchmatch criteria | cpe:2.3:a:jenkins:gitlab:*:*:*:*:*:jenkins:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.