Database/Control plane, storage & DevOps
Jenkins XL Deploy plugin: any user with Overall/Read can enumerate stored credential IDs
Impact
Missing permission checks let anyone holding Overall/Read list the IDs of credentials stored in Jenkins. The secrets themselves are not returned, so this is reconnaissance rather than theft: it tells an attacker which registry pushes, kubeconfigs, cloud roles and node-bootstrap keys this controller holds, and gives them the exact IDs to reference in a later pipeline-injection or plugin bug. On a controller that deploys to GPU clusters, the credential list is effectively a map of what the CI system can reach in the fleet. Low severity on its own; it matters mainly as the first step of a chain, and only on controllers that actually have the XL Deploy plugin installed.
Who can reach it
Remote authenticated Jenkins user with only Overall/Read permission (PR:L). No job configuration rights and no user interaction are needed.
What to do
Upgrade the XebiaLabs XL Deploy plugin past 26.1.0 per SECURITY-3948 in the 2026-09-02 Jenkins advisory; the advisory names 26.1.0 and earlier as affected without stating a fixed release number, so take the current plugin version. Cost is a controller restart to load the plugin - queue pause, agent reconnects, running builds lost unless drained. If XL Deploy is not in use here, uninstalling the plugin removes the exposure and is cheaper than tracking its releases.
References
Related entries
- Jenkins update-center2: unescaped plugin metadata gives stored XSS on plugin download index pagesCVE-2026-84677 · Jenkins update-center2 (plugin metadata escaping on download index pages)Medium
- CloudNativePG instance manager (status server, TCP/8000 control endpoints): A set of operator-only control endpointsNCVD-2026-050-cloudnativepg-instance-manager-s · CloudNativePG instance manager (status server, TCP/8000 control endpoints)Medium
- Slurm (user_name / gid field handling): Slurm trusts the user_name and gid fields carried in job RPCs instead ofCVE-2018-10995 · Slurm (user_name / gid field handling)Medium
- IBM Spectrum LSF (job submission, file permissions): Weak file permissions in the LSF install let a local user changeCVE-2018-1724 · IBM Spectrum LSF (job submission, file permissions)Medium
- AMD IOMMU host buffer access - insufficient RMP checks (AMD-SB-3016): Insufficient RMP checking on IOMMU host bufferCVE-2023-20585 · AMD IOMMU host buffer access - insufficient RMP checks (AMD-SB-3016)Medium
- ZKTeco BioAccess IVS v3.3.1 access control platform: An unauthenticated attacker can open and close any doorCVE-2023-38958 · ZKTeco BioAccess IVS v3.3.1 access control platformMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.