CVE-2026-70444: Security vulnerability
A missing permission check in Jenkins Violation Comments to GitLab Plugin 2.62.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
A missing permission check in Jenkins Violation Comments to GitLab Plugin 2.62.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
CVE-2026-70444 has a risk rating of 33, indicating it poses a moderate threat to security.
CVE-2026-70444 exploits a missing permission check that allows unauthorized users to enumerate stored credential IDs.
To fix CVE-2026-70444, upgrade to Jenkins Violation Comments to GitLab Plugin version 2.62.1 or later.
Any Jenkins instance using Violation Comments to GitLab Plugin version 2.62.0 or earlier with Overall/Read permission granted can be affected.
CVE-2026-70444 can lead to credential information exposure, risking unauthorized access to sensitive data.