Jenkins Horreum Plugin 0.16.162.v33b_4a_a_b_5f828 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to have Jenkins send credentials they are not entitled to use to the administrator-configured Horreum URL.
Metrics
Affected Vendors & Products
References
History
Wed, 05 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Improper Credential Context in Jenkins Horreum Plugin Allows Unauthorized Credential Leakage | |
| Weaknesses | CWE-200 CWE-269 CWE-284 |
|
| Metrics |
cvssV3_1
|
Wed, 05 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jenkins Horreum Plugin 0.16.162.v33b_4a_a_b_5f828 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to have Jenkins send credentials they are not entitled to use to the administrator-configured Horreum URL. | |
| References |
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2026-08-05T19:37:23.588Z
Reserved: 2026-08-04T14:13:20.603Z
Link: CVE-2026-70443
Updated: 2026-08-05T19:37:18.075Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-05T20:15:12Z