{"id":"GHSA-f696-867g-2759","summary":"Jenkins OpenTelemetry Plugin missing permission check allows capturing credentials","details":"A missing permission check in Jenkins OpenTelemetry Plugin 3.1543.v8446b_92b_cd64 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.","aliases":["CVE-2025-58460"],"modified":"2025-11-05T21:06:50.587578Z","published":"2025-09-03T15:30:34Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2025-09-03T22:23:42Z","nvd_published_at":"2025-09-03T15:15:39Z","cwe_ids":["CWE-862"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-58460"},{"type":"WEB","url":"https://github.com/jenkinsci/opentelemetry-plugin/commit/f5a4ec123769096ad9a4930ede56588b0fee40f3"},{"type":"PACKAGE","url":"https://github.com/jenkinsci/opentelemetry-plugin"},{"type":"WEB","url":"https://github.com/jenkinsci/opentelemetry-plugin/releases/tag/3.1543.1545.vf5a_4ec123769"},{"type":"WEB","url":"https://www.jenkins.io/security/advisory/2025-09-03/#SECURITY-3602"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/09/03/4"}],"affected":[{"package":{"name":"io.jenkins.plugins:opentelemetry","ecosystem":"Maven","purl":"pkg:maven/io.jenkins.plugins/opentelemetry"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1543.1545.vf5a"}]}],"versions":["0.1-alpha","0.10-beta","0.11-beta","0.12-beta","0.13","0.14","0.15","0.16","0.17","0.18","0.19","0.2-alpha","0.20","0.21","0.22-beta-1","0.22-beta-2","0.22-beta-3","0.22-beta-4","0.3-alpha","0.4-alpha","0.5-beta","0.6-beta","0.7-beta","0.8-beta","0.9","1.0.0","1.0.1","1.1.0","1.1.0-rc1","1.1.0-rc2","1.1.1","1.2.0","1.2.0-rc1","1.2.0-rc2","1.2.1","2.0.0","2.0.0-alpha-1","2.0.0-beta-1","2.0.1","2.1.0","2.1.0-rc1","2.1.0-rc2","2.1.0-rc3","2.1.0-rc4","2.1.1","2.10.0","2.10.0-beta-1","2.10.1","2.11.0","2.12.0","2.12.0-rc1","2.13.0","2.14.0","2.15.0","2.16.0","2.17.0","2.17.0-beta1","2.18.0","2.18.0-beta1","2.19.0","2.2.0","2.2.1","2.2.2","2.3.0","2.3.0-rc1","2.4.0","2.5.0","2.5.1","2.6.0","2.6.0-rc1","2.7.0","2.7.1","2.7.1-rc1","2.7.1-rc2","2.8.0","2.8.0-rc1","2.8.0-rc2","2.8.0-rc3","2.9.0","2.9.0-rc1","2.9.1","2.9.1-beta-1","2.9.2","3.1086.v955c8a_c4d90a_","3.1092.va_2a_c52b_dd182","3.1111.vc2733c03b_db_1","3.1135.vdcdb_17548474","3.1138.v80fc844ed246","3.1205.v862c5d236ecc","3.1209.v1d64463d3d6c","3.1215.vc9db_a_0b_34c2a_","3.1261.v46101e2a_3660","3.1270.v35d71e4855f1","3.1293.vb_c48573e17a_4","3.1298.vb_3b_a_5d878dda_","3.1310.vfe6b_821a_4ed2","3.1314.vb_3104190d2da_","3.1320.v2eededb_d909e","3.1368.vb_f1dcb_e6595c","3.1383.v32c9f94458e3","3.1391.vcb_a_a_b_9779d75","3.1419.v3b_27ca_911066","3.1423.v0d1a_2fcd2429","3.1464.va_85780e90d4c","3.1475.v21037899cf33","3.1480.v23e541c0fcb_4","3.1487.vf27fcf83deb_b_","3.1490.vfd3786616d1d","3.1494.v1d249433404c","3.1495.v64dcff5b_7a_6c","3.1503.v0696f14605b_b_","3.1505.v69c4d7c9ee62","3.1513.va_7b_d9d2324e5","3.1515.v1b_2d6b_526498","3.1520.vd981c197a_43f","3.1523.v0b_3ce640987d","3.1525.v604f3b_1a_e07b_","3.1543.v8446b_92b_cd64"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-f696-867g-2759/GHSA-f696-867g-2759.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"}]}