← Vulnerability feed

Vulnerability record · CVE-2025-24397 · published 22 January 2025

CVE-2025-24397: Jenkins gitlab incorrect authorization vulnerability

Jenkins · Gitlab

An incorrect permission check in Jenkins GitLab Plugin 1.9.6 and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credential IDs of GitLab API token and Secret text credentials stored in Jenkins.

4.3 CVSS 3.1 Medium EPSS 0.30% · top 79.7% CWE-863 · Incorrect authorization
4.3CVSS 3.1 base score
0.30%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

An incorrect permission check in Jenkins GitLab Plugin 1.9.6 and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credential IDs of GitLab API token and Secret text credentials stored in Jenkins.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-24397 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2019-10301Jenkins gitlab missing authorization vulnerabilityA missing permission check in Jenkins GitLab Plugin 1.5.11 and earlier in the GitLabConnectionConfig#doTestConnection form validation method allowed …EPSS 1.3%8.0CVE-2019-10300Jenkins gitlab cross-site request forgery vulnerabilityA cross-site request forgery vulnerability in Jenkins GitLab Plugin 1.5.11 and earlier in the GitLabConnectionConfig#doTestConnection form validation…EPSS 1.3%6.5CVE-2022-30955Jenkins gitlab missing authorization vulnerabilityJenkins GitLab Plugin 1.5.31 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to …EPSS 0.89%5.4CVE-2022-34777Jenkins GitLab Plugin stored XSS in webhook build descriptionsJenkins GitLab Plugin 1.5.34 and earlier fails to escape multiple fields inserted into the description of webhook-triggered builds, creating a stored…EPSS 73%analysed5.3CVE-2022-43411Jenkins gitlab observable discrepancy vulnerabilityJenkins GitLab Plugin 1.5.35 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token a…EPSS 0.72%9.1CVE-2026-71362Adobe commerce incorrect authorization vulnerabilityAdobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vul…KEVEPSS 88%8.8CVE-2026-42016JFrog Artifactory token scope bypass enables privilege escalationJFrog Artifactory (Self Hosted) before 7.133.11 validates a token's signature and issuer but not its scope, so a token can be used for actions beyond…KEVEPSS 8.6%analysed10.0CVE-2025-54253Adobe Experience Manager Forms misconfiguration allows pre-auth code executionAdobe Experience Manager Forms 6.5.23 and earlier contain a misconfiguration (CWE-863, incorrect authorization) that lets an attacker bypass security…KEVEPSS 88%analysed

Source: NIST National Vulnerability Database (record CVE-2025-24397), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.