PT-2026-93776 · Jenkins · Gitlab Plugin
CVE-2026-92133
·
Published
2026-09-16
·
Updated
2026-09-16
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins GitLab Plugin versions prior to 1.2149.vcfc32c82b f7f
Description
The plugin caches the GitLab API client for alternative GitLab API token credentials using a cache key based solely on the credentials ID, failing to include the folder where the credentials are resolved. This allows users with Item/Configure permissions to access GitLab API token credentials they are not authorized to use.
Recommendations
Update the Jenkins GitLab Plugin to a version later than 1.2149.vcfc32c82b f7f.
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gitlab Plugin