Description

Missing permission checks in Jenkins HCL AppScan Plugin 1.8.3 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

Affected products

VendorProductVersions
Jenkins ProjectJenkins HCL AppScan Plugin0 to <=1.8.3

References

Authoritative sources

This page is a snapshot. For the latest enrichment and updates, view the record on CVE.org or the NVD.

Generated from the official CVE List on 06 Aug 2026 07:06 UTC.