CVE-2025-24397: Jenkins GitLab
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
An incorrect permission check in Jenkins GitLab Plugin 1.9.6 and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credential IDs of GitLab API token and Secret text credentials stored in Jenkins.
Affected products
- Jenkins GitLab: up to and including 1.9.6
Published 2025-01-22. Last modified 2026-06-17.