GHSA-p8jh-4p5p-2rfp

Suggest an improvement
Source
https://github.com/advisories/GHSA-p8jh-4p5p-2rfp
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-p8jh-4p5p-2rfp/GHSA-p8jh-4p5p-2rfp.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-p8jh-4p5p-2rfp
Aliases
Published
2026-05-27T15:33:27Z
Modified
2026-07-01T20:11:28Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Jenkins Job Import Plugin does not perform a permission check in an HTTP endpoint
Details

Jenkins Job Import Plugin 143.v044a_2e819b_27 and earlier does not perform a permission check in an HTTP endpoint.

This allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. Those can be used as part of an attack to capture the credentials using another vulnerability.

An enumeration of credentials IDs in Job Import Plugin 143.145.v48f9a_a_6ff384 requires Job Import/Import Jobs permission.

Database specific
{
    "cwe_ids":  [
        "CWE-269"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-07-01T19:45:17Z",
    "nvd_published_at":  "2026-05-27T15:16:32Z",
    "severity":  "MODERATE"
}
References

Affected packages

Maven / org.jenkins-ci.plugins:job-import-plugin

Package

Name
org.jenkins-ci.plugins:job-import-plugin
View open source insights on deps.dev
Purl
pkg:maven/org.jenkins-ci.plugins/job-import-plugin

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
143.145.v48f9a

Affected versions

1.*
1.0
1.1
1.2
1.3
1.3.1
1.5
1.6
1.7
1.8
2.*
2.0
2.1
3.*
3.0
3.1
3.2
3.3
3.4
3.5
3.6
122.*
122.v35289550f1e6
143.*
143.v044a_2e819b_27

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-p8jh-4p5p-2rfp/GHSA-p8jh-4p5p-2rfp.json"