GHSA-f696-867g-2759
MODERATECVE-2025-58460A missing permission check in Jenkins OpenTelemetry Plugin 3.1543.v8446b92bcd64 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
- Affected
- < 3.1543.1545.vf5a
- Fixed in
- 3.1543.1545.vf5a
- Weakness
- CWE-862
- Published
- 2025-09-03
- Source
- github