Search
Search Results (2 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-92133 | 1 Jenkins Project | 1 Jenkins Gitlab Plugin | 2026-09-17 | 5.4 Medium |
| Jenkins GitLab Plugin 1.2149.vcfc32c82b_f7f and earlier caches the GitLab API client built for alternative GitLab API token credentials under a cache key derived from the credentials ID alone, omitting the folder in which the credentials are resolved, allowing attackers with Item/Configure permission to access GitLab API token credentials they are not entitled to use. | ||||
| CVE-2026-84664 | 1 Jenkins Project | 1 Jenkins Gitlab Plugin | 2026-09-03 | 5.4 Medium |
| Jenkins GitLab Plugin 1.9.16 and earlier allows overwriting the global GitLab connection configuration through Stapler data binding, allowing attackers to connect to an attacker-specified URL using GitLab API tokens already configured by administrators. | ||||
Page 1 of 1.